The SSH listener refused a disabled account, but the API and the web reach Dispatch directly and never checked the flag, and disabling deleted browser sessions while leaving API tokens alive. Dispatch now refuses a disabled account outright, and SetUserDisabled revokes its API tokens along with its sessions, so re-enabling means minting again.
TestDisabledAccountAPI: a token answers before disable, 401 after, still 401 after re-enable, while the account itself is back over ssh.
Closes #95