Ported from PR #198 (Rosmi720/XC_VM): shared category templates were only
visible to the sharer's direct sub-resellers. Widen visibility to the whole
hierarchy so a template shared by any ancestor reseller reaches every
descendant.
- getTemplatesForUser: walk the ownership chain upward (new cycle-guarded
ancestorOwnerIds helper) and match is_shared templates owned by any
ancestor, not just the direct parent.
- canAccessTemplate: accept a shared template when the caller sits anywhere
in the owner's sub-tree; this subsumes the old direct-parent check.
- Reseller list: add a "Shared with Me" scope tab + count, driven by the
existing scope_type='shared' classification.
- Add CategoryTemplateVisibilityTest covering ancestor visibility and the
access guard (also keeps both methods under the CRAP ratchet).
Deliberately excluded from PR #198: the admin category_template(s) view
rewrites (a competing older implementation that reintroduces the xcToast
argument-order bug and drops the ?create=1 dialog deep-link already fixed
locally), and its language/RTL/active-code/dashboard changes (out of scope).