Since #6203 the set-options endpoint stores the value returned by the
options validator. The validator replaces "!secret x" with the resolved
secret before type-checking, so the plaintext secret ended up in the
persisted app options instead of the reference (#7152).
Make the validator non-destructive on request instead of restoring the
references afterwards: AppOptions gains a resolve_secrets flag. When it
is False, a "!secret x" value is still validated against the resolved
secret (including the pwned hash and type coercion) but the reference is
returned. The set-options endpoint validates with resolve_secrets=False,
while write_options and the self options config endpoint keep resolving
secrets for the container.
Fixes#7152
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>