4793d77fa9
RevertFact voids the latest fact for a key — a store mutation — but /api/revert had no step-up gate, while POST /tools required L3. Close the inconsistency: thread the same *webauthn.PasskeySession into handleRevert and reject with 403 when a configured session isn't asserted. nil session (WebAuthn unconfigured) keeps prior behavior — transport-level auth only. Tests: un-asserted session → 403 and RevertFact not called; asserted → 200. The RevertFact mock now records its key so the gate assertion is meaningful. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>