fix(settings): stop leaking provider keys; relabel recovery action Open Thinking master
Harden the Settings/Thinking ownership boundary. - GET /app/settings/api/config now projects `env` over the settings-owned allowlist only (REVAI_ACCESS_TOKEN + PLAUD_ACCESS_TOKEN), mirroring runtime_env, instead of booleanizing every journal env entry. Google/OpenAI/Anthropic key presence and arbitrary vars no longer leak; provider config is already stripped. A recursive-sentinel test proves no provider name / model id / endpoint field / cloud-key presence / arbitrary env can leak through any response subtree. Settings write allowlist + CLI still reject thinking-provider keys; Thinking stays the sole owner of provider config. - Collapse the duplicate-target _SETTINGS_ACTION into _THINKING_ACTION so every recovery action pointing at /app/thinking/#main reads "Open Thinking" across the Python presenter, the hand-maintained chat_reasons.js mirror, health/readiness payloads, API baselines, and the browser test. _LOCAL_SETUP_ACTION (Open Local Model Setup) is unchanged. Python↔JS parity holds.