login: skip unreachable legacy entry for non-default --server, redact URL errors
main·
Commit

Address PR #1404 review comments and the broken login integration tests:
- Every legacy-keyring read keys by api.AuthBaseURL(), which is always the default origin now — a legacy entry saved under a non-default --server origin was unreadable forever and undeletable by logout (Bugbot's logout finding, fixed at the write side instead). For a non-default server the context is the sole record of the login, so RecordLoginContext failure becomes fatal there instead of a warning.
- parseLoginServer errors now echo u.Redacted() rather than the raw flag value, so a password in a rejected userinfo URL can't land in CI logs.
- The login integration tests still exported the retired ENTIRE_AUTH_BASE_URL (rejected at startup since 6e40fcaa432) and served the v1 device-code path the default split-host provider no longer uses. They now pass --server, serve /device_authorization, mint an iss-bearing fake JWT (context recording needs claims), and sandbox ENTIRE_CONFIG_DIR/token store so the spawned binary can't touch the real ~/.config/entire or OS keychain.
Co-Authored-By: Claude Fable 5 noreply@anthropic.com Entire-Checkpoint: 6849b1e6a444
Checkpoints
Checkpoint 1