Expand description
Shared CLI auth helpers (#28).
Centralizes the acquire_service_auth orchestration — get a
Cairn-bound service-auth token from the operator’s PDS, with
one-shot refresh-and-retry on a 401 from getServiceAuth. The
refresh path also persists the rotated tokens back to the
session file on disk so the next CLI invocation starts with
current credentials (§5.3).
Callers (cli/audit.rs, cli/report.rs, cli/retention.rs, cli/trust_chain.rs) used to carry byte-identical local copies of this function. Factoring threshold per session N3 was 6+ identical copies; the trust-chain CLI (#37) brought the count to 8 callsites across 4 modules and tripped the rule.