EHBP (Tinfoil) forwarding buffered responses through an h11 client with a
hard-coded 30-second inactivity timeout. Slow first-token latency or
queueing on larger models would trip it, surfacing a bare 500 instead of a
meaningful timeout.
- Bump the default EHBP timeout from 30s to 60s.
- Introduce EhbpTimeoutError (subclass of UpstreamError, code
UPSTREAM_TIMEOUT, status 504) raised from connect/send/read timeouts.
- Bearer auth now surfaces a proper 504 via the existing UpstreamError
handler instead of a generic 500.
- X-Cashu requests refund the redeemed amount and return a 504 with the
refund token.
Adds tests for timeout conversion, exception metadata, and the X-Cashu
refund-on-timeout path.