fix(files): refresh URL auth token proactively for asset previews
The oc_url_token has a ~50s effective lifetime and was only fetched once at preview mount, so HTML/image/PDF previews cycled to 'authentication required' when it expired and nothing forced a re-render with a fresh token. Add a consumer-gated proactive refresh in runtime-auth: while at least one url-token consumer is active, a single scheduler mints a fresh token just before the skew window and swaps it in atomically (the previous token stays valid until the new one lands — no empty-token window for other consumers). acquire/release manage the consumer count; subscribe fires only on a real token replacement. FilesView consumes this via a shared useAssetAuthRefresh hook (replacing three near-duplicate effects) and remounts the iframe/img only when the token actually changes, not on a blind interval.
This commit is contained in: