Timing Attack Fix #1660
Replaced fail-fast string comparison with constant-time SHA-256 hashing via
crypto.timingSafeEqual. Added 6 Vitest unit tests. Verified against 1,777-test suite with
zero regressions. CWE-208 patched.