Add planespotters.net latest-photo lookup for ADS-B aircraft.
- app/live_layers.py: fetch_planespotters_photo() (hex preferred, reg
fallback) + _normalize_planespotter_photo(); 24h TTL cache (their ToS cap).
- app/main.py: GET /api/aircraft/photo?hex=...|reg=... (422/404/502).
- app/static/index.html: .ps-photo block in ADS-B popup; lazy load on
popupopen; thumbnail links to photo page + photographer credit.
Server-side proxy, not browser fetch(): planespotters 403s any request
carrying an Origin header (every browser fetch() sends one). The thumbnail
binary is loaded by the browser straight from their CDN, never re-hosted.
Tests: 4 unit + 4 API contract (38 pass in the two files).