55181a7d79
The local expires_in countdown killed OAuth sessions with a bare "Session expired" before the backend poller's enriched message (Portal sign-in stalled in the opened tab, retry/API-key fallback) could reach the UI, and the desktop onboarding poller had no local expiry at all — a dead session polled forever. Both surfaces now lapse with guidance naming the common cause, prefer the backend error_message when it has one, and keep polling when the backend still reports pending (clock skew).