When the gateway answers `confirm_required` (large cached context,
expensive model, data-training tier), the Desktop asked for confirmation in
a warning toast with a single "Confirm" action and an ✕ — no button meant
"no", Enter/Esc did nothing, the four-item toast stack could evict the
pending question, and the guard's `\n`/`\n\n` paragraphs collapsed into one
run-on line. Answering after the session had moved on was a silent no-op.
`surfaceModelSwitchConfirm` (THE shared applier for both surfaces — the
composer picker via `config.set` and the Bots editor via
`profiles.configure`) now asks through `confirm()` from `@/store/confirm`,
i.e. the shell-mounted ConfirmDialog that apps/desktop/DESIGN.md names as
the only way to ask "are you sure": destructive "Switch anyway" vs "Keep
current model", Enter confirms, Esc/backdrop/✕ decline, the dialog owns
focus. Declining is free — nothing was applied before the answer. A stale
confirmed answer now toasts "Selection changed — the model switch was not
applied" instead of doing nothing. ConfirmDialog renders its description
`whitespace-pre-line` so backend-composed paragraphs survive. The applier
resolves `true`/`false` instead of returning a notification id; callers
fire-and-forget it. New i18n keys land in all six locales.
Slim redo of #112463 by @DavidMetcalfe (design: route through confirm(),
labels, stale notice). #112461 by @KoNit-K was the earliest filer (Cancel
action on the toast) and is superseded by the dialog.
Fixes#112458
Co-authored-by: DavidMetcalfe <80915+DavidMetcalfe@users.noreply.github.com>
Co-authored-by: KoNit-K <124019182+KoNit-K@users.noreply.github.com>