fix(auth): auth token --jurisdiction mints from the active context, not data-host discovery
Commit

entire auth token --jurisdiction resolved its exchange subject via
resolveStoredCellSubject, which discovers a login context against the
data host (api.BaseURL(), default entire.io). With multiple contexts,
selectContext only lets the active context win if it is eligible for
that host — so a user with an active partial.to context (and the default
entire.io data host) had the mint silently fall back to their entire.io
context, always producing an entire.io-audienced token. Plain
entire auth token was unaffected because it uses the active context
directly.
Resolve the stored jurisdiction subject from the ACTIVE login context
instead (resolveActiveContextCellSubject): its refreshed login JWT is the
subject and its own core drives the environment family and exchange
target, matching plain auth token. Only JurisdictionToken changes;
NewEntireAPICellClient still uses resolveStoredCellSubject (it dials the
data plane, where data-host discovery is correct). The ENTIRE_TOKEN path
is unchanged.
Rewrites TestJurisdictionToken_StoredContext to seed an active context and adds TestJurisdictionToken_StoredContextFollowsActiveContext (two contexts, partial.to active → partial.to audience).
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 01KXDA1NB3T9QS453736ZT98RZ