b6b7802447
Widen the cron-only clearing to `_unattended_contexts()`: a webhook / api_server session running inside a gateway inherits HERMES_EXEC_ASK=1 exactly like an external cron worker does, and `_presence()` returning is_ask=True sent it to the gateway-decision branch with no notifier — a pending card nobody can answer — instead of `approvals.unattended_mode`. Same class as #110932, one predicate. Test trimmed to two invariants (cron / webhook leak → cleared; interactive keeps presence); the launch-path comment in cron/scheduler.py names the env-fallback consumers instead of an internal incident log.