applyToken
Re-applies the auth credential to the retried request.
Delegates to authProvider so the correct scheme is used regardless of auth type (Bearer, ApiKey, Basic, Cookie, Custom).
If no authProvider is set (e.g. cookie-only auth where Ktor handles cookies automatically via KHttpConfig.cookieStorage), this is a no-op — the updated cookie storage is already picked up by io.ktor.client.plugins.cookies.HttpCookies.