Enhance Otto's configuration approach by:
- Separating normal configuration from secret configuration for better security
- Replacing GitHub PAT authentication with OIDC through GitHub App auth
- Ensuring secure handling of webhook secrets and tokens
This will improve security posture and follow best practices for sensitive credential management.
Based on feedback from PR #3: #3 (comment)