Add `authorization-manager-ref` and `use-authorization-manager` to `<http>`, similar to `<websocket-message-broker>` support.