Desktop sessions landed in state.db with an empty user_id even after a
password login: the backend resolved the identity at WS-upgrade auth (it
writes login_success with the right user_id to logs/dashboard-auth.log) and
stamped it on the session record as auth_user_id, but the row-creating write
never passed it on — and user_id is only ever set at insert, so no later,
identity-aware writer could fill it.
_ensure_session_db_row and _persist_branch (branch children) now stamp the
same <provider>:<id> identity the agent is built with. Anonymous records
carry no login, so those rows keep their empty user_id exactly as before.