8900fb2cf8
force_refresh_token gated the adopt-from-disk paths behind the failure cooldown. After one of our exchanges failed transiently, a 401 within the next 30s returned None even when a sibling process had already rotated and written a valid grant, so the operation raised HonchoAuthError with a good token sitting on disk. Adopting is a disk read, not an exchange; the cooldown exists to stop replaying a single-use refresh token, so the two adopt checks now run before the gates. _write_config parsed honcho.json twice under the lock and only wrapped the first read into ConfigWriteRefused; _refuse_unparseable now returns the parsed dict and the branches use it. The getattr/isinstance duck-typing collapses to one guard. cli._read_config reuses oauth's tolerant reader (BOM-tolerant, like the strict reader the write side uses) instead of its own utf-8 copy.