auth: silent login-token refresh for git-remote-entire
Commit

Device-flow login now requests offline_access, captures the returned
refresh token through the poll plumbing, and persists it to the paired
<service>:refresh keyring slot. git-remote-entire's login-JWT provider
is now refresh-aware: an expired login JWT is re-minted from the refresh
token instead of failing the operation with a re-login.
The provider is backed by auth-go's tokenmanager, which serialises refreshes across processes (advisory file lock) and goroutines and persists the rotated refresh token. That matters because the server issues single-use refresh tokens with reuse detection + family revocation: two concurrent git-remote-entire processes (e.g. a recursive submodule fetch) racing a naive refresh would replay the same token and get the whole family revoked. A thin per-context tokenstore.Store adapter maps the keyring slots onto tokenmanager.
Behaviour is a strict superset of before: a still-valid token is returned with no network call, and a context with no refresh token (a login predating this change) behaves exactly as it did — valid token used, expired token surfaces a re-login error.
Server-side support already existed in entire-core (offline_access on the device grant, refresh_token grant for the public client, rotating single-use families), so no server changes are required.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 0192d919e856