Per Oso docs: map NotFoundError to 404 and ForbiddenError to 403, ideally in one global error handler.

Context: Problem: A call to authorize fails when no allow rule matches, and you need the right HTTP status. Oso raises two distinct errors: NotFoundError when the user should not even know the resource exists (they lack read permission) - handle by returning 404 Not Found. ForbiddenError when the user can see the resource (has read) but may not perform the action - handle by returning 403 Forbidden. Note a read check never raises ForbiddenError, only NotFoundError. Handle both globally in middleware rather than at every authorize call site.

## Matched source
Source: Source: https://www.osohq.com/docs/oss/node/guides/enforcement/resource.html
Original query: "Oso authorize throws NotFoundError vs ForbiddenError - map them to 404 vs 403"
Key terms: authorize, forbiddenerror, notfounderror, them, throws
