cli: add `entire login --server`, retire ENTIRE_AUTH_BASE_URL (COR-393)
Commit

entire login --server <url> (default https://us.auth.entire.io)
replaces the env var as the way to target a non-default login server.
The value is validated as a bare http(s) origin — userinfo, path,
query, and fragment are rejected rather than silently dropped, since
it becomes the OAuth issuer, exchange target, and keyring key.
A set ENTIRE_AUTH_BASE_URL (even empty) now fails every built-in command with a hint naming the flag: a removed knob must never be silently ignored. Internal api.AuthBaseURL() reads survive until the follow-up demolition PR, but can only ever observe the default now.
auth.NewClient takes the server explicitly instead of reading the env var; login's TLS check narrows to the server actually being dialled.
Co-Authored-By: Claude Fable 5 noreply@anthropic.com Entire-Checkpoint: 5036f0366fb3