space: log managing-app denials and honor ZDS_PLC_DIRECTORY master
A managing-app space answered UserNotAuthorized from getSpaceCredential without recording why. Resolution failure, a failed checkUserAccess request, and a non-authorizing answer all returned false silently, so a report of a denied requester whose managing app never saw the check could not be diagnosed from logs. Each of those now logs the space, managing app, endpoint, and error or upstream status. Spaces DID resolution always used plc.directory regardless of ZDS_PLC_DIRECTORY. It now follows the configured directory, which also lets the permissioned smoke stand in a managing app: the suite covers a grant, the service-auth claims and query the app receives, and denial on authorized=false, a missing field, 401, and 500. That path had no end-to-end coverage. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>