iEduPortal API v1 — Stage 27

Adds a protected read-only dashboard summary endpoint at /api/v1/dashboard/.

Admin/staff receive safe school overview counts plus latest session/active term.
Parents receive child and unread-message counts.
Pupils receive unread-message count and their linked class.

No passwords or authentication credentials are returned.
No database schema changes.
