Document the redirect design and the blockers holding apply master
Work is paused: the Tangled site endpoints are not reachable on the flagship appview, and the autosync service needs fixes before anything is committed to GitHub, since one-way sync makes every GitHub write a live Tangled change. Records the client-side redirect design for old GitHub Pages URLs, including the routing behaviour that makes a single 404.html on the user site sufficient, and the hostname guard that keeps a synced shim from redirecting Tangled to itself. Adds CLAUDE.md covering the facts that took effort to establish — XRPC_ENABLED defaulting off, the service-auth audience, where repoDid lives, the two tngl.* domains — and the constraint that GitHub writes propagate unattended.