invalidate Session State
Drop in-memory auth state derived from a prior response (Google's captured session= token, Cesium Ion's per-asset access token) so the next fetch is forced through the full auth bootstrap. Called when the caller detects auth rejection (e.g. 401/403 on a content fetch) and is about to refetch root.json to obtain a new session/token. Default no-op for stateless providers.