Unlock all locally gated features without a sponsor token. The change sits
in util/sponsor/auth.go instead of the ~68 device constructors:
- Subject defaults to a non-empty value, so RedactedStatus reports an active
sponsorship and the frontend unlocks isSponsor
- IsAuthorized always returns true, opening every caller including the
modbus proxy and the optimizer gate
- ConfigureSponsorship still validates a configured token but never fails,
so an expired token no longer aborts startup
Drops TestAlpitronicSponsorGate and TestSigenergyEVDCSponsorGate, which
asserted exactly the gate that is removed here.
Cloud-backed services (optimizer API, remote access, cloud vehicles,
telemetry) still require a real token - those are checked server side.
See FORK.md.