b60dc669ea
- Fenced final OAuth refresh update and terminal-disable CAS statements by row id, serialized credential data, active lease owner, and unexpired lease time. - Passed an AbortSignal through MCP OAuth token refresh and bounded owned refresh operations below the lease TTL while awaiting the aborted fetch to settle. - Added regressions for stolen-lease update/disable attempts and timed-out MCP token fetch abort behavior. Fixes #5081