build: adopt spl-rust v0.11.0, where the capability is the whole bridge admission check master
The private-link bridge used to forward only an eight-header allowlist (plus the route-class marker) and refuse any request that carried Authorization or a reserved header, even when it held the capability. A request holding the capability is this app's own code, so that was a policy against itself. v0.11.0 forwards every header the bridge does not reserve and strips (never refuses) the reserved ones; the exact loopback Host and the capability remain the admission check. The explicit header allowlist is removed with the library's policy knob. The test that pinned the refusal now pins what replaces it: reserved caller headers are stripped on the way through, and a request without the capability is still refused before it reaches the journal. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>