Message authentication: real HMAC signing and verifying
This release completes the cryptographic core the previous one started. Where 0.1.86 added real hashing, this adds real message authentication: crypto.subtle can now import a raw HMAC key and sign and verify with it, over any of the four hashes already present (SHA-1, SHA-256, SHA-384, SHA-512). The implementation is standard HMAC and was checked byte-for-byte against the published RFC 4231 test vector - signing produces the exact expected code, verifying accepts the true message and rejects a tampered one. Together with the hashing from the previous release, this is the path that JSON Web Token verification, signed webhooks and API-request signing take, so code that authenticates a request now gets a correct answer instead of a broken fallback. The engine gate holds at 6375 of 6375 and the work carries a test against the standard vector. This is a capability release rather than a coverage move: SubtleCrypto still lacks encryption and key generation, so the Web APIs figure holds where it honestly is.