fix(auth): don't let the default data origin mask a staging login in jurisdiction mint
Commit

entire auth token --jurisdiction (and the shared entire-api cell URL
templating) derive their prod-vs-staging "environment family" via
environmentFamily(dataOrigin, discoveredCore). The stored-context path
(resolveStoredCellSubject) sets dataOrigin to api.BaseURL(), which
defaults to prod entire.io when ENTIRE_API_BASE_URL is unset — so a
partial.to login minted a token audienced to https://us.entire.io
instead of https://us.partial.to, which a partial.to cell rejects. The
ENTIRE_TOKEN path was already correct (it passes the token's own core as
dataOrigin).
Fix the shared resolution: only an EXPLICIT ENTIRE_API_BASE_URL override wins; otherwise the discovered login core (which issued/trusts the JWT being exchanged) determines the family, so a partial.to login yields a partial.to audience even with the data origin left at its prod default.
Also introduce familyEntireIO/familyPartialTo constants for the two apex strings. Adds TestEnvironmentFamilyPrefersDiscoveredCoreOverDefaultOrigin.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 01KXD78RRFFBDJF08RHTW0DEK9