The perm client accepts `http?: EngineHttp` for transport, but the
service factory previously did not forward `App.http` automatically. An
app that declared both `http` and `perm` had to wire them together by
hand or pass `endpoint` + a custom `fetcher`.
`defineActivePerm` now declares `serviceDependencies: ['http']` and
forwards `App.http` to `createActivePerms({ http })` when:
- the caller did NOT pass `options.http` (explicit wins)
- AND did NOT pass `options.fetcher` (caller signaled their own
transport — leave `http` undefined to avoid double-wiring)
Apps without `http` declared keep working — `services.http` is
`undefined` and we leave the `http` slot empty.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>