- api_clients bekommt ein m2m-Feld `products` (Mehrfachauswahl) über die neue
Junction `api_client_products`; das Einzelfeld `product` bleibt als Fallback.
- POST /v1/orders: neues Pflichtfeld `product` (Produkt-Key) wählt aus den
erlaubten Produkten; bei genau einem optional. Ungültig/fehlend → 400 mit
Liste der erlaubten Keys.
- POST /v1/clients akzeptiert `products: [id, …]`.
- Doku (Swagger UI) + OpenAPI um das product-Feld ergänzt.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>