requireFreshAuthNext
Session lock (#14): force the next ensureSeedReady to require a fresh biometric, even if the Keystore auth-validity window is still open. Delegates to SeedVault.requireFreshAuthNext; called by SessionLock on lock so the unlock genuinely re-authenticates rather than silently re-decrypting within the window.