Adds a contract test that runs `createProjectSupabaseClient()` against
the real `@supabase/supabase-js` for each Supabase API key format
(temporary, publishable, secret, legacy JWT), asserting that client
construction succeeds. Also replaces the placeholder key fixtures in the
existing unit tests with realistically shaped ones. Previously the tests
mocked the SDK entirely and used keys that don't resemble real formats,
so an SDK version that rejects a valid key at construction (as
`@supabase/supabase-js` 2.110.4 and 2.110.5 did, reverted in #47945 and
fixed in supabase/supabase-js#2526) passed CI unnoticed; with this test,
such a regression fails on the dependency bump PR itself.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Tests**
* Added coverage confirming project clients work with temporary,
publishable, secret, and legacy API key formats.
* Updated test scenarios to use realistic temporary API key values.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->