SAKEN Platform Phase 7.27 — Document Approval & E-Signature

Added:
- Document Approval section on the main Saken All dashboard.
- Same Saken All login/session; no second login screen.
- Permission checkbox in Users & Permissions.
- Central approval-user profiles stored in D1.
- Admin can link an existing Saken All username/email and define request, approval, stamp, management and audit permissions.
- Khalid can be configured for signature only or signature + stamp per workflow.
- Password change inside Approval updates the same Saken All password through /api/change-password.
- General ordered approver workflow and TECNICAS ADDENDUM workflow retained.

Deployment:
1. Run RUN_THIS_IN_D1_PHASE7_27_DOCUMENT_APPROVAL_SSO.sql in D1.
2. Deploy worker/saken-platform-api-worker.js.
3. Upload the full package to Cloudflare Pages.
4. From Users & Permissions, grant Document Approval & E-Signature to required users.

Important prototype limitation:
PDF files, saved signatures and document history are still stored in the browser in this HTML prototype. Cross-device direct approval links and centrally shared PDFs require the next backend step: Cloudflare R2 document storage plus server-side approval-document APIs.

Optional users:
- Run OPTIONAL_CREATE_APPROVAL_USERS_PHASE7_27.sql only if the five requested accounts do not already exist.
- Temporary password: Saken@2026.
