5fff41e52e
1Password/Bitwarden items can carry several websites, but both backends collapsed the item's urls[]/uris[] to the first origin that normalizes, so browser_vault_fill refused every other explicitly saved origin with origin_mismatch. Reordering the URLs in the manager just moved which single origin worked. VaultItemMeta now carries allowed_origins (every normalized, deduped web origin; origin stays the first/primary one). Fill matching stays exact-origin against that list — no wildcard, parent-domain or subdomain inference — and the in-page synchronous check pins the origin actually matched via build_fill_js(expected_origin=page_origin). App URIs such as androidapp:// never widen the fill set.