Provider connections now enforce the permission boundary
The connection screen is now a focused provider picker instead of a wall of credential forms. BeforeRed only offers new connections when the provider credential can be restricted against infrastructure changes.
- One provider flow at a time, with the capability boundary shown before any credential input
- Nine permission-restricted connection paths are implemented: five restricted-token paths and four OAuth paths
- Railway OAuth is registered with project-viewer access and refresh support; Supabase, Vercel, and Neon remain provider-setup dependent
- Legacy broad credentials are paused and can be removed without deleting prior usage history