feat(services): mint consent links at request time, drop server-side browser master
Optional hosted-service enable flows (SPL in apps/link, scout in apps/thinking) opened a browser on the journal host and only revealed a manual consent link if that open reported failure. On a headless/remote journal the host-side open reports bogus success, suppressing the link and stranding the UI at "setting up…". Now the enable route mints the nonce and builds the consent URL at request time, returns it in the 202 operation payload, and the background poll reuses that same nonce. The web UI opens it one-tap client-side (window.open) and always renders a persistent "continue to approve →" link; the start button is hidden while the operation is non-terminal and restored on terminal. The CLIs echo the consent URL unconditionally. Removes the server-side browser path entirely: the webbrowser imports, _open_browser/open_for_handoff/_tracked_opener, the open_browser params, and the browser_open_succeeded field on HandoffResult/OperationEntry and the API payload. The operation entry now owns portal_url from creation, and _update_entry_from_result no longer overwrites it on terminal. Request-time build failure (SPL instance resolution OSError) returns a real error_response instead of a stranded 202. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>