security: fix session, LDAP, and rate limiting gaps master
Revoke OAuth tokens on user suspension and check user status in userinfo so suspended users actually lose API access. Distinguish LDAP "user not found" from infrastructure errors (network, bind failure) so an LDAP outage doesn't trigger mass account suspension or deletion. Track orphaned_since from first authoritative detection rather than account creation for a real grace period. Skip destructive actions when LDAP errors occur. Consolidate passkey routes on shared session helpers that check user status, eliminating divergent session parsing and giving suspended users no passkey management access. Uniform LDAP error responses to prevent user enumeration. Rate limit dynamic client registration (5/min per IP), token endpoint (30/min per IP), and device code verification (10 failures/15min per user). Require HTTPS for redirect URIs (http allowed only for loopback). Add NODE_ENV=test to preload so rate limiters skip in tests. 💘 Generated with Crush Assisted-by: Crush:kimi-k3