-- audit3-followup (2026-05-29): User.passwordChangedAt for session rotation.
-- Additive nullable column. Existing rows have NULL = "never rotated" so
-- no existing session is invalidated by the migration itself. The session
-- callback compares JWT iat against this timestamp; a NULL value means
-- "always valid" (pre-PR behaviour preserved). Population happens on the
-- next password change.

ALTER TABLE `User` ADD COLUMN `passwordChangedAt` DATETIME(3) NULL;
