10652c9345
fetchJson/fetchPublicJson only reached the redirect diagnostic when the 3xx carried an HTML body or text/html content-type; an empty-body 302/307 (the common reverse-proxy / forward-auth shape) still resolved null through the earlier empty-body check. http.request never follows redirects, so classify on status first and reject every 3xx with the redirect error regardless of body. Pass res.headers.location through so the message says where the request was sent, and stop blaming credentials when the Location differs from the requested URL only by scheme or trailing slash -- that is a saved-URL mismatch, not an authentication proxy. Drop the 404 mention from the docstring/test: both callers reject >= 400 before this branch, so only the 2xx leg carries the endpoint-missing capability wording. Part of #112072