auth: discovery-only data-API resolution, delete TokenForResource (COR-393)
main·
Commit

ResolveDataAPIToken loses both static fallbacks: a host that doesn't advertise /.well-known/entire-api.json (or has no parseable host) is now an error naming the host — without discovery we can't know which login servers it trusts, and guessing risks exchanging a token at a core the host doesn't accept. entire.io#2277 shipped the well-known, so the old-deployment case the fallback existed for is gone.
With its last callers removed, TokenForResource and the process-wide singleton manager go too, along with the SetManagerForTest / DiscoveryUnavailableForTest seams and the test scaffolding that only existed to pin the fallback path.
Co-Authored-By: Claude Fable 5 noreply@anthropic.com Entire-Checkpoint: 7056101a1d83
Checkpoints
Checkpoint 1