6fc301d62c
Review found that execRedacted was applied only to the new remote-enumeration code and left three pre-existing calls reading remote.origin.url through the plain, unredacted exec: removeUserInfoFromHttpsOrigin, requireCredentialFreeHttpsOrigin, and configureHttpsUrlRewriteForSshOrigin. A non-zero exit or timeout on any of those could still have copied the credentialed URL into a WorktreeException message. Switches all three to execRedacted; the set-url write in removeUserInfoFromHttpsOrigin is left on plain exec with a comment explaining why (it writes the already-stripped URL, not a read). Widens the shared exec(Map, boolean, String...) overload to package-private, the same test-seam pattern already used by the afterWorktreeAdded constructor parameter, and adds a test that drives it directly with a synthetic failing command whose stdout carries a marker (passed via env, not argv, so the always-printed command line can't carry it) and asserts the marker never reaches the exception message.