Port of Rosmi720/XC_VM@4e91fb68. Encrypted playlist entries carried the output
extension as a URL fragment (play/<token>#.<ext>), which the client strips and
nginx never sees, so every encrypted stream fell back to .ts — VOD/HLS were
effectively broken. Encode the extension in the path instead:
- PlaylistGenerator emits play/<token>.<ext> for live and VOD (Cloudflare TS
keeps the bare token). The live/VOD suffix is a small pure helper
(encryptedPlaySuffix, unit-tested) so generate() stays within its ceiling.
- nginx rewrites play/<token>.<ext> to the auth handler, keeping the legacy
play/<token>/<ext> and bare-token rules for already-saved playlists.
- stream/auth.php splits a <token>.<ext> token and fills the extension when
nginx did not.
- settings label uses the new encrypt_playlists key (en.ini).
Adapted to this tree: ar.ini is absent here, so only en.ini was updated.