Two requests ignored the domain mapping from #238 and went to STALWART_URL:
- /api/account/* re-fetched the upstream session without upstreamFor(), so
once the five-minute session cache expired, password, app-password and
2FA calls for a mapped domain reached the default server.
- The locale lookup resolved Stalwart's apiUrl against the default server
rather than the one that issued the session.
Both now use the session's own server, with a test pinning the second.