Stop credential tokens leaking into usage output
Commit

Token flags registered their env value as the pflag default (e.g. StringVar(&auth.Token, "source-token", envOr("GITSYNC_SOURCE_TOKEN", ""))). pflag prints non-empty defaults in --help, and the unknown-flag fallback in main.go dumps the full usage block to stderr — so a typo'd flag in a CI job with GITSYNC_*_TOKEN set wrote the credential into CI logs.
Register secret flags (source/target token + bearer-token, including the inlined ones in convert-sha256) with empty defaults and apply the env value after parsing via a PreRunE hook, only when the flag was not given explicitly. An explicit flag still wins over the environment.
Add chainPreRunE so independent flag helpers can each attach post-parse logic without clobbering one another, and route allRefsFlag through it too.
Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 409a151aeced