fix(logging): scrub stderr the way oauth.jsonl is already scrubbed master
`logging/oauth.rs` states that nothing secret is ever written to the log and makes that structural with `Fp`. The `--debug` channel made no such promise and kept none: `dump_err` printed `{e:#?}` raw on the same jacquard error the next line in `auth.rs` passed through `scrub_text` on its way to the log, at some thirty call sites. Both entry points into `logging/debug` scrub now, so the guarantee belongs to the channel rather than to whoever wrote the call, and `dump_err` routes through `log`, which gives a `{:#?}` dump the one-`[debug]`-per-line shape this module documents. `scrub_text` itself only blanked *quoted* values, so `access_token=abc123` walked through whole: the `=` and then the letters of the value were skipped as punctuation and the scan gave up on the first digit. The shape is reachable — `RequestError` carries the request URL, query string and all, and `{:#?}` prints it. Bare values are blanked too now, but only after an `=`, which keeps `refresh_token: None` and the word "code" in a pull request body readable under `--debug`. The doc claimed the opposite of what the code did and now says what happened. Also the one site in `auth.rs` that printed an `oauth-state` nonce in full, where every other one fingerprints it through `redact_key`. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>