* security: placeholder committed door-unlock token + rotation runbook (INFRA-105)
The live door-system auth token was hard-coded in the Yealink Push-XML
provisioning templates (both /unlock and /lockdown) and present in git
history since 2c9b863. Replace it with __DOOR_UNLOCK_TOKEN__ so future
templates carry no secret; add RUNBOOK-token-rotation.md covering the
rotation, phone re-provisioning, and history scrub.
Rotation + history scrub are NOT performed here — staged for a scheduled
phone re-provisioning window. The old token is compromised until rotated.
* security: mark INFRA-105 rotation executed; correct false cache-expiry claim
The runbook claimed the old token stops working ~5 min after SSM rotation.
/sh-security-review (2026-07-06) confirmed this is false: the authorizer and
both handlers cache the token in module scope with no TTL, so warm containers
honor the old token until recycled (unbounded). Add the mandatory forced
cold-start step, mark the cutover EXECUTED (token rotated to SSM v3, history
scrubbed + force-pushed, Lambdas recycled), stop embedding partial token bytes,
and note the accepted refs/pull/* residual. Design fix (cache TTL) tracked.