Fix ServiceAuth token expiration and spindle URL handling master
ServiceAuth token fixes: - Reduce expiration from 600 to 60 seconds for method-less tokens per AT Protocol spec (fixes BadExpiration error) Spindle URL handling: - Support URLs with or without protocol prefix (e.g., "spindle.vitorpy.com") - Add protocol (https://) automatically in xrpc_url() when missing - Extract host correctly for ServiceAuth audience DID in both cases - Read spindle URL from repo's spindle field for secret operations - Fall back to TANGLED_SPINDLE_BASE env var or default Secret operations fixes: - Add new post() method for endpoints that return empty responses - Update add_repo_secret() and remove_repo_secret() to use post() instead of post_json() (fixes JSON parsing error on empty response) - All secret operations now connect to correct spindle instance Other improvements: - Add spindle field to RepoRecord struct - Display spindle URL in repo info output - Ensure all three secret operations (list, add, remove) use the repo's configured spindle instance