Remove unused mobile OAuth support (v2.0.0)
Breaking change: Removes mobile-specific features that were unused by the
iOS app (which uses cookie-based auth via WebView instead):
- mobileScheme config option
- mobile and code_challenge query params on /login
- Mobile callback with session_token redirect
- Bearer token auth in getSessionFromRequest()
Now focuses solely on cookie-based session management.
Updates @tijs/atproto-sessions to 2.0.0.