SSLCommerz hosted checkout

{{--

Log in on this host first (POST /api/newlogin) so the token cookie is sent. Submitting starts GET /api/sslzcheckout with bo_in_id and payment_amount; the server responds with a redirect to SSLCommerz.

--}}
{{--
1) If no bo_payment_info row exists yet, checkout creates one (same as POST /api/init-payment-status).
2) After payment → /sslzcheckout.
3) Store mode: SSLCZ_SANDBOX in .env.
--}}