JwtBearer middleware does not run for WebSocket upgrade requests, so
HttpContext.User is anonymous inside Blazor Server components. Fall back
to manual cookie parsing + token validation (same pattern used by
EnvelopeReceiverAuthorizationService). Cache the resulting principal on
HttpContext.User for subsequent calls within the same circuit.
Also inject IOptionsMonitor<JwtBearerOptions> and IOptions<AuthTokenKeys>
to support the validation path.