git-remote-entire: address PR review on ENTIRE_TOKEN path
main·
Commit

- Redact userinfo in CoreURLFromEnvToken error messages (u.Redacted()) so a malformed aud with credentials can't leak to stderr/logs.
- Fail closed with a clear "ENTIRE_TOKEN is set but blank" message on a whitespace-only token instead of the raw JWT-parse error; truly empty is still treated as unset by the caller and falls back to context auth.
- Rename "core" -> "login server" in resolveCreds doc comments.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: b5f6f2ff8832
Checkpoints
Checkpoint 1