feat(sync): serve com.atproto.repo.getRecord on the public XRPC surface master
The Coves AppView's profile backfill fetches missed social.coves.actor.profile records via com.atproto.repo.getRecord, but the bridge only served the sync.* CAR endpoints — so all 857 bridged users' profile fetches died on a bare 404 and their avatars could never be reconciled. This adds the repo.* JSON read form, reviewed by a 12-stream multi-model pass (specialty agents, pragma:security, Go validators, Codex, Kimi K3) with all accepted findings folded in. Changes: - internal/sync/server.go: new handleRepoGetRecord behind the shared per-IP limiter; repo param accepts a DID or bridged handle (optional HandleResolver, satisfied by identity.Resolver; resolution failures fold into RepoNotFound so probing learns nothing the DID path wouldn't reveal); optional cid pin is parsed (malformed → 400) and compared canonically; deactivated-repo consent gate reused via the loadActiveRepo → loadActiveRepoByDID extraction - internal/repo: GetRecord now walks the MST root-to-leaf via mstPathToRecord (extracted from GetRecordProof) instead of materializing the whole tree — a security-review catch: the eager load handed an unauthenticated caller a full-repo read per request; shared readHeadCommit helper dedupes head-commit decoding with loadTree - cmd/tidepool/main.go: wire the store-backed handle resolver into the sync server - tests: happy path, handle resolution (@-prefix, unknown, validation and internal resolver errors), cid pin (canonical, alternate encoding, mismatch, malformed), invalid collection, missing params/record/repo, deactivated repo, rate-limit sweep - README: document the endpoint on the sync-surface list Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>