fix(auth): use DPoP authentication for user write operations master
Replace plain Bearer token authentication with proper DPoP-authenticated OAuth sessions for subscribe, unsubscribe, block, and unblock operations. The issue was that atProto OAuth tokens are DPoP-bound and require both an access token AND a DPoP proof header. The community service was using plain Bearer authentication which caused "Malformed token" errors. Changes: - Update Service interface to use *oauth.ClientSessionData - Add PDSClientFactory pattern for testability - Update handlers to get OAuth session from middleware - Update unit tests to inject OAuth session into context 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>