A request can wait to be served for longer than the access token it was
sent with lives, and comes back refused for a token that was valid when
it left. Uploads that take minutes make that wait ordinary.
- tell an expired token apart from any other refusal by the code the
API returns, and retry only that one, once
- prefer a token another process left behind over minting a second: it
saves a round trip, and a rotating provider would retire one that is
still in use. Assign it rather than read it, since the setter is what
rewrites the session header the retry will carry
- settle the token before the request so the one compared afterwards is
the one that was actually sent
- report an overloaded server when the second attempt is refused too,
and let API errors out of the upload path with their own type