Remove DPoP key exposure from SDK public API, harden session types
Remove generateDpopKeyPair, createDpopProof, and generatePkce static
methods — WASM handles these internally now. Make OAuthSession token
fields readonly. Add security warning to Identity type. Log proactive
refresh failures instead of silently swallowing them.