b364c53c61
Avatar rendered a bare <img> with no error handling, so an avatar_url whose storage object is unreachable (e.g. a 404 after the server move) showed a broken image instead of the coloured letter-circle fallback. Track an onError flag and fall back to the circle; reset it when the URL changes so a fresh valid avatar is retried. This is client-side resilience only — it does not restore a genuinely missing storage object. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>