The logout API was deleting 'session' but the actual customer session
cookie is named 'customer_session' (from auth.ts SESSION_COOKIE).
This fix ensures the logout properly clears the customer session, so users
are actually logged out when the browser closes.
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>