docs, scripts: stop referencing retired ENTIRE_AUTH_BASE_URL
Commit

README and the device-auth smoke script still told developers to export
the retired var, which now makes every entire command exit at the
startup gate. Both switch to entire login --server. The smoke script
also catches up with reality: login prints "Login URL:" (not "Approval
URL:"), and a --server login records a contexts.json context instead of
a legacy auth.json entry, so verification reads contexts.json.
Stale comments describing the env var as a live fallback/override are reworded ("the default auth origin"), the upstream-host-resolution doc no longer points at the removed AuthBaseURLOverridden, and a coreapi test sentinel stops advising the retired var.
The mechanism itself (the env read in api.AuthBaseURL and the tests that t.Setenv it) stays for the part-2 demolition PR, per the plan in the PR description.
Co-Authored-By: Claude Fable 5 noreply@anthropic.com Entire-Checkpoint: 889d3caa19b7