Add a CalDAV token fixture (kind=4) for user10 who has TOTP enabled, and implement the previously-skipped test proving token-based auth still works when TOTP is active.