Decides whether a request for a surface's root must first choose a realm.
It asks only for a GET or HEAD of exactly the surface's root in the default
realm, with realms defined; the caller has already found no session. A
choice is a redirect built from the registry's own prefix, never an echo of
the request.
Parameters
req: ChooserRequest
the express request
surfaceId: string
'admin' or 'portal'
Returns Decision
null to sign in here; { kind: 'page', error } to draw the
chooser (with a sentence when the id asked for is no realm); or
{ kind: 'redirect', location } to the chosen realm's surface
Decides whether a request for a surface's root must first choose a realm.
It asks only for a GET or HEAD of exactly the surface's root in the default realm, with realms defined; the caller has already found no session. A choice is a redirect built from the registry's own prefix, never an echo of the request.