Correct cluster-resolution comments to match actual token flow

main

Commit

toothbrush3mo ago

The resolver comments claimed not persisting a cluster binding prevented a "drive-by clone" from minting identity-bearing JWTs. That's false: the login JWT only ever goes to the resolved context's CoreURL, never to the cluster host, and the cluster host receives only a repo-scoped, audience-pinned token. Reframe not-persisting as the correctness choice it is (immediacy of auth use / context deletion, no host-controlled host->core mapping lingering), and align the auth-contexts audit comment.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: ee378db97d3e

Checkpoints

Debug Cluster Context Git Remote Lookup

Claude CodeOpus 4.8[1m]
View session
Checkpoint 1