feat(mcp): encrypt OAuth credentials at rest and expire idle connections
A1 — encrypt the secret fields of an OAuth connection (access/refresh/id tokens,
client secret, PKCE verifier) with AES-256-GCM keyed by MCP_OAUTH_ENCRYPTION_KEY.
Metadata (expiry, scope, client_id, CSRF state) stays plaintext so projections and
lookups are unchanged. Values are tagged 'enc.v1:'; decryption passes through
untagged legacy plaintext, so existing records migrate lazily on rewrite and an
unset key keeps today's plaintext behavior (with a startup warning). Encrypt on
write, decrypt at point-of-use; the redundant tokens.refresh_token match in the
refresh path is dropped in favor of the version guard.
B1 — authenticated connections get a 90-day sliding idle TTL (previously none),
refreshed on each use via the existing deleteAt TTL index, so abandoned grants
don't persist forever.
Adds crypto round-trip tests and documents MCP_OAUTH_ENCRYPTION_KEY in .env.