e65ddf1c7b
createPrimaryRemoteConnection() rebuilt the primary remote descriptor field by field and left out `headers`, so every REST call routed through fetchJsonForBackend() (Settings profiles/config, session history) reached the gateway without the configured extra headers while chat, the Test button and the readiness probe -- which read the exact-URL WebSocket header store or the resolved route directly -- kept working. Behind an access proxy (e.g. a service-token gate) those REST calls came back as a 302 to the login page. Carry `headers` through the descriptor like every other rebuild site (buildRemoteConnection, the registry pool path and both ensureRegistryBackend reuse branches already spread it), and pin it with an invariant test on the existing primary-descriptor seam. Fixes #112072 Co-authored-by: plluviera <plluviera@users.noreply.github.com> Co-authored-by: KoNit-K <124019182+KoNit-K@users.noreply.github.com>