Validate a clone URL's authority as it was typed
Commit

entire://real-cluster.entire.io@evil.com/gh/a/b resolved to evil.com
and would be dialled — the CLI fetching /.well-known/entire-cluster.json
from a host the URL never appeared to name, out of a string a user
pasted because it looked like their cluster.
validateClusterHost was never wrong: it refuses userinfo explicitly. It just never saw any, because the check ran on url.Parse's Host, which has the userinfo stripped off by then. Cutting the authority out of the literal text is what puts it back in front of the check. The cut splits on "//" rather than the scheme constant, so a differently-cased scheme — which url.Parse accepts — cannot slip past.
The doc comment claimed this boundary held while the code did not enforce it. I had measured that gap earlier, deleted the failing test case as out of scope, and left the claim standing, which is worse than never having looked.
Two texts the ULID removal left behind: badRepoRefErr still offered "a
repo ULID" among the forms to pass, and the conventions still documented
repo view as taking one. Neither is reachable now.
Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com Entire-Checkpoint: 01M3PV5SSC6BN0W4ARHWCVPWSP