eccf39dded
Maintainer follow-up to the #72763 salvage: check_photon_token_valid() now delegates to the existing validate_photon_token() (session lookup + /api/projects/) instead of a bespoke get-session-only probe, since the device flow can mint tokens that pass the session check but fail the project APIs that setup actually uses. Semantics preserved: definitive auth rejection = stale, transient errors = probably-valid.