knotserver: bind git push service auth lxm
Use an explicit service-auth lexicon method for Git receive-pack discovery and POST routes instead of deriving lxm from Git smart-HTTP path segments such as info/refs or git-receive-pack. This lets real HTTPS pushes present a PDS-issued service auth token scoped to sh.tangled.git.receivePack.
Patch category: upstreamable-core