Root cause: onboarding_complete existed as dead code (a module-level function
with 'self' param, never registered as a DRF @action). The template JS posted
to /accounts/users/onboarding/complete/ which 404'd.
Fix: added a POST handler to the existing ui_views.onboarding_complete view
that accepts JSON {username, password, password_confirm, signature}, calls
OnboardingService.complete_wizard (sets password, clears is_provisional,
sets acknowledgement_completed), and notifies admins. Updated the template
JS fetch URL to /accounts/onboarding/complete/ (the working endpoint).
Re-verified (headed): token activation → welcome → wizard steps → checklist →
activation form → POST completion → is_provisional=False, ack=True. ✅
Remaining: the browser JS submitActivation() has a timing/CSRF issue that
prevents the fetch from completing on button-click (the direct POST works).
Needs separate investigation.