Authentication

BookNest's sign-in is still the setUser('Ana') placeholder from Auth Flows, and its checkout sends orders without proving who placed them. This section replaces both: the practice API becomes a small OAuth 2.0 authorization server, and the app signs in through the system browser with expo-auth-session (57.0.13), keeps the tokens in expo-secure-store, refreshes them when they expire, and asks for a fingerprint with expo-local-authentication (57.0.3) before reusing a saved sign-in. npx expo install expo-auth-session expo-web-browser expo-crypto expo-local-authentication adds them; they need a new development build.

Subsections