* reset-password: rotate the admin credential in place instead of deleting auth.db
* reset-password: fix the CI callers and error handling for the in-place rotation
* [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
* reset-password: narrow the CI change to the jobs that read .bootstrap_password
* reset-password: stop over-claiming what the reset revokes and when it takes effect
* auth: bind token issuance to the credential version that was verified
* auth: bind credential-creating writes to the version the request authenticated with
* [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
* auth: bind the change-password and workflow-key writes to their own credential version
* [pre-commit.ci] auto fixes from pre-commit.com hooks
for more information, see https://pre-commit.ci
* auth: read the credential version inside the transaction that validated it
* data-recipe: answer 401 when a reset revokes the credential mid job start
* Fix lint blocker and Windows path assertion for PR #7573
Drop the now-unused validate_api_key import from studio/backend/auth/authentication.py.
Every call site moved to validate_api_key_with_credential, so the Source lint job's
import-hoist gate flagged it as a blocker. The wrapper itself stays in storage.py;
test_api_key_expiry.py still exercises it.
Make test_run_reexec_forwards_resolved_frontend_on_public_launch compare against
str(Path(...)) instead of a POSIX literal. _find_frontend_dist returns a Path, so on
Windows the forwarded value is \fake\studio\frontend\dist and the assertion could
never pass there. Pre-existing, surfaced by running unsloth_cli/tests on Windows.
---------
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
Co-authored-by: Daniel Han <danielhanchen@gmail.com>