The dashboard route pre-wrote only secrets to .env and then called
install_entry, which prompted again for every auth.env var on a non-TTY
server stdin — the user's supplied non-secret value was read as EOF,
discarded, and config.yaml ended up with an unresolved ${VAR} ref
(asana: silent OAuth break; n8n: hard 400 on the required URL).
install_entry now accepts preloaded_env (dashboard form values) and
_prompt_env_vars skips the prompt for any spec already supplied, so the
route passes body.env straight through and the non-secret inline path
works end-to-end. The boundary test now exercises the real install_entry
(dashboard route, no mock) and asserts the non-secret lands in the server
config; asana manifest comments updated to match the inline behavior.