Stage 38 — Fee Summary API

GET /api/v1/fees-summary/
Authorization: Bearer <access_token>

Read-only summary of fee obligations, payments, deductions and estimated balance.

Filters: session, term, pupil_id.

Scope:
- pupil/student: own obligations and linked parent payment/deduction history
- parent: own children and family payment/deduction history
- admin/approved staff: all records or a selected pupil

No schema changes. Passwords and credentials are never returned.
