personal memory agent

refactor(convey): remove web-UI password, login, and session auth master

port 5015 is loopback-only, and mtls on 7657 is the sole network transport as of 0.6.0, so the web password gated nothing. remove the login form, flask session-cookie login, http basic auth, the trust_localhost localhost bypass, the journal password cli, and the convey.secret/app.secret_key flask-session machinery. refactor the require_login gate to require_access while keeping private link revocation auth and the first-run /init onboarding redirect. there is no migration: orphan convey.password_hash, convey.secret, and trust_localhost keys in existing journal.json files are ignored, and _NEVER_TRANSFER_PATHS still scrubs password_hash and secret on export. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>


+339 -1459
128 changed files