Stage 33 — Search API

GET /api/v1/search/?q=<term>&type=<optional>&limit=<n>&offset=<n>
Bearer-token protected, read-only search across class, subject, announcement,
classwork, assignment and e-library metadata. Pupil/parent results are class-scoped.
No binary content or credentials are returned. No schema changes.
