c902f50efb
createMediaProtocolHandler() set only the session token / bearer on the /api/files/stream request. The descriptor it resolves now carries the connection's extra gateway headers, but the handler never read them, so attachments in session history from a header-gated remote still bounced off the access proxy even though every fetchJsonForBackend() call got through. Merge connection.headers into the media request before auth, letting the forwarded range/cache negotiation headers win, and pin it on both the token and the OAuth cookie-session legs. Part of #112072