fix(auth): derive jurisdiction mint environment from the active context
Commit

entire auth token --jurisdiction <slug> (-j) mints a jurisdictional
identity token, and the shared entire-api cell resolution templates the
audience/exchange-core from an environment "family". Both derived that
family from the data-API origin, which defaults to prod entire.io when
ENTIRE_API_BASE_URL is unset — so a partial.to login minted a token
audienced to https://us.entire.io (iss https://us.auth.entire.io),
which a partial.to cell rejects. Plain entire auth token was already
correct because it keys off the active login context's core_url.
Fix at the shared resolution point:
environmentFamilyno longer lets the default data origin mask the login environment. An explicitENTIRE_API_BASE_URLstill wins; the default falls through to the discovered login core (the core that issued/trusts the JWT being exchanged), so a partial.to login yields a partial.to family.- New
auth.MintJurisdictionIdentityTokenexchanges the caller's login credential (active-context JWT orENTIRE_TOKEN) for a jurisdictional identity token whose environment is taken from the context core, never a constantentire.iobase. - Wire it into
entire auth tokenbehind--jurisdiction/-j.
Before (active context us.auth.partial.to): aud=https://us.entire.io. After: aud=https://us.partial.to (exchange at https://us.auth.partial.to). The entire.io context is unchanged.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 879dcfce8ae4