2f01ec9fa4
Second follow-up for salvaged PR #94547, folding in review findings from the duplicate-PR cluster (#47015, #55054, #58476, #72977, #73685 all fix the same 401) and the sweeper review of #73685: - Replace the dot-anchored suffix predicate with exact-match against the existing _ALLOWED_TEAMS_SERVICE_HOSTS allowlist (two of the five duplicate PRs converged on this independently). Any Azure customer can register <name>.trafficmanager.net profiles, so suffix matching was not safe. Also requires https on the default port — :444 on an allowlisted host no longer receives the bearer (sweeper finding on #73685). - Stream _fetch_attachment_bytes through _read_httpx_body_with_limit instead of buffering response.content — the shared inbound media cap now applies to authenticated downloads too (sweeper finding: a lying Content-Length must not OOM the gateway). - Serialize token refresh with a lazily-bound asyncio.Lock so concurrent attachments share one STS POST (review finding on #94547). - Token expiry now uses time.monotonic() (from #55054) — wall-clock jumps can't extend a stale token. - Tests updated: exact-allowlist predicate (lookalike/subdomain/port/scheme negatives), streaming fake client, and a concurrent-cold-cache lock test. Mutation-checked: suffix match, silent drop, no-lock, and unbounded buffer each fail a test.