648d858bb1
#purgeSupersededDisabledRows matched disabled rows against active ones by exact identity-key string equality, but the active-replacement path it mirrors (matchesReplacementCredential) claims pre-org legacy rows (`<b>` vs `<b>|org:<o>`). So a later org-scoped login of the same account never purged the pre-org tombstone, which then rendered forever as a red row in `omp usage` with no CLI/TUI escape. This is the OAuth half of the class of bug #2943 fixed for api_key rows in the same function. Reuse matchesReplacementCredential in the purge so an org-scoped login claims and hard-deletes its pre-org tombstone, inheriting the one-way upgrade and shared-workspace guards unchanged. Fixes #7876