feat: RFC 8707 resource indicators (token audience binding) master
Bind access tokens to a specific resource server so a token minted for one service can't be replayed at another (the token-reuse hole the MCP auth spec closes). - migration: add a nullable `resource` column to authcodes, device_codes, tokens. - resource.ts: validate/normalize resources (absolute URI, no fragment) and, for the consent screen, resolve each to a friendly name + icon via its RFC 9728 Protected Resource Metadata (SSRF-safe, hostname fallback). - authorize (GET auto-approve + POST consent) and device: read, validate, and persist the requested resource; the consent page shows WHAT is being granted access to (logo + name) and carries it through as hidden fields. - token: thread the resource through all three grants (auth code, device, refresh keeps its audience) and echo it as `aud` from introspection so a resource server can verify the token was minted for it. Unscoped tokens (no resource requested) behave exactly as before.