extractToken accepted Authorization values with no scheme prefix,
silently treating them as per-request tokens. The stateless-http-auth
spec mandates bare tokens be rejected and treated as no header. Drop
the fallback branch so unrecognized/scheme-less values fall through to
the global singleton instead of forging an identity.
- operation: extractToken returns "" for scheme-less headers (task 2.5)
- test: extractToken case-insensitivity + bare-token rejection (4.4)
- test: ephemeral-client construction failure surfaces error, no
singleton downgrade (4.3)
- docs: cross-link stateless-http-auth OpenSpec change from README (5.2)
- tasks: mark completed blocker fixes (1.3, 2.4, 2.5, 4.2-4.4, 5.x, 6.3)