refactor(observer): retire legacy DL key-in-URL ingest surface; key_prefix→prefix master
Now that the shipped capture clients use keyless Authorization: Bearer (+ PL fingerprint) and :5015 is loopback-only, remove the legacy key-in-URL observer-ingest surface end to end. - Drop the `/X/<key>` route forms on ingest_upload, ingest_manifest, ingest_manifest_day, ingest_event, ingest_segments, and delete_source; the keyless siblings authenticate via PL fingerprint then Bearer. - Delete the dead ingest_transfer route + its require_login exempt entry and structural-gate test entry (zero production callers). - Strip the url_key auth fallback from resolve_observer_identity / _get_auth_key: identity is PL-fingerprint-first then Bearer, with no third fallback. Absent credentials now return auth_required (not the misleading auth_key_invalid). - Collapse the DL arm out of `transfer.py`: remove the URL/key send client, its orphaned helpers, and the DL constants; `transfer send` is PL peer-label only. _normalize_url is retained (export.py imports it). - Rename the observer wire field key_prefix→prefix on /api/list, /api/create, and /init/observers (shared _serialize_observer), the /api/list sort tie-break, and both workspace.html readers. URL route params, internal log fields, and the import-app key_prefix are unchanged. - Document E2 (peer = provenance, not a behavioral role) and E3 (observer-ingest vs import-ingest are deliberately separate) in code comments. The observer callosum SSE route stays keyed (/app/observer/<key>/callosum) so shipped Bearer-capable Linux/macOS chat bridges keep working; its <key> segment is now vestigial (unused for auth). The keyless /app/observer/callosum conversion is a deferred coordinated-client follow-up.