9cc881ce5b
Remote OAuth MCP servers dropped out of /mcp under `omp auth-broker serve` once their access token expired: neither the client nor the broker could complete the refresh. - Client: the MCP manager threw on the broker-redacted refresh sentinel (REMOTE_REFRESH_SENTINEL) instead of asking the broker to refresh. It now routes redacted MCP refreshes through AuthStorage.forceRefreshCredentialById, which calls back to the broker (the real refresh token never leaves the broker host). - Broker: the serve process had no mcp_oauth:* refresh path, so POST /v1/credential/:id/refresh answered "Unknown OAuth provider". Its AuthStorage is now built with a refreshOAuthCredential override that refreshes MCP credentials with a generic refresh_token grant from the credential's embedded token endpoint and client id. The background refresher keeps MCP tokens live through the same path. Extract shared refreshManagedMcpOAuthCredential and mcpOAuthServerUrlFromCredentialId helpers so both paths use identical refresh material selection and RFC 8707 fallback-resource logic. Fixes #8933