Three defensive fixes from Bugbot review:
1. SetOAuth2TokenSource disables cloud and found endpoints when a token
source is set. OAuth2-authenticated requests carry a Bearer token and
must only go to explicitly configured verification endpoints, never to
native cloud APIs where the token could leak.
2. Add Attempted field to VerifyOutcome, set at the top of each loop
iteration. When Attempted is true but Definitive is false, verification
was configured but every endpoint failed (transport error, token
acquisition failure). Callers now surface this as a verification error
instead of silently reporting the secret as unverified.
3. Infer Content-Type from the body when no explicit header is set.
Template-resolved bodies (always valid JSON) get application/json;
raw secret bytes get text/plain. Prevents mislabeling non-JSON
payloads as JSON in the engine path.
Co-authored-by: Cursor <[email protected]>