The desktop's sync_unlink and the ffi's unlink were both written out in full: try
the revoke, clear the link either way, and log the outcome. link::unlink(db, held)
now does that. Each client reads its link with state::credentials (with its seal)
before the await and passes it in.
DRY pass #2, batch 1, F3 (#5372).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The desktop's sync_link and the ffi's link_with_password/link_with_token were
the same steps written out twice: probe, refuse an incompatible server before
any credential is sent, log in or verify a pasted token, keep the link, and adopt
the server's trash retention. link::authenticate(url, Credential) does the
network half and link::store(conn, ..., seal) keeps it, sealed when the client
has a seal. Each client now only reads its input and picks its seal.
The desktop checks for a missing email/password before probing rather than after.
Same error, sooner.
DRY pass #2, batch 1, F2 (#5372).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>