78ef6805f3
ExtensionRunner.emitAfterProviderResponse accepted the response model but discarded it, calling createContext() with no model. Response-scoped hooks therefore saw the primary session model in ctx.model and ctx.models.current() even when the response came from a cross-provider side request, so an extension that revokes a credential on an HTTP 402 could target the wrong provider. Call createContext(model) to match emitBeforeProviderRequest, plus a regression test asserting both fields expose the response model. Fixes #8955