fix(api): register CORS outermost so error responses stay readable

Starlette's add_middleware inserts at index 0, so the LAST registration wraps
every earlier one. CORS was registered first, making it innermost: any
middleware that short-circuited above it returned a response that never passed
through CORS and so carried no Access-Control-Allow-Origin header.

A browser cannot read such a response — it reports an opaque net::ERR_FAILED
and the real status and message are lost. The encryption middleware's 400
"Request body is not a valid encrypted payload" hit exactly this: a client
built without --dart-define=AES_ENCRYPTION_ENABLED=true saw an unexplained
network error instead of the reason its request was rejected, which cost a
long stretch of misdiagnosis during UAT.

Registering CORS last also means preflight OPTIONS is answered before the
tenant and encryption layers see it. The inverted comment on the encryption
block is corrected too.

Also carries accumulated in-progress work from this branch that predates and
is unrelated to the UAT run.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
