applyAuthHeaders
Stamps Authorization and, if the account is DPoP-bound, a DPoP proof header on builder. No-op when UserAccount.getAuthToken is null or empty. Rejects an incomplete DPoP credential with IOException before mutating builder.