Correct cluster-resolution comments to match actual token flow
main·
Commit

The resolver comments claimed not persisting a cluster binding prevented a "drive-by clone" from minting identity-bearing JWTs. That's false: the login JWT only ever goes to the resolved context's CoreURL, never to the cluster host, and the cluster host receives only a repo-scoped, audience-pinned token. Reframe not-persisting as the correctness choice it is (immediacy of auth use / context deletion, no host-controlled host->core mapping lingering), and align the auth-contexts audit comment.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: ee378db97d3e
Checkpoints
Checkpoint 1