• Fetches temporary AWS credentials from POST /v1/user/credentials.

    Shared by ESPRMNeoUser.getTemporaryAWSCredentials and callers that need identity-pool credentials (e.g. AssumeRole / MQTT setup) without depending on prototype attachment order.

    Flow:

    1. Ensure a non-expired Cognito ID token (refresh session if needed).
    2. POST credentials with Bearer ID token.
    3. On 401 expired-token, refresh the session and retry (up to MAX_CREDENTIAL_RETRIES times).
    4. Persist and return the temporary credentials.

    Returns Promise<ESPAWSCredentials>

    Temporary AWS credentials (access key, secret key, session token, expiration).

    If the user is not logged in (missing ID/refresh token).

    On network failure, incomplete response, or non-retryable API error.