Restore granular token traversal in GraphQL type authorization

Problem

The type-level granular PAT authorization work in !238311 (merged) and !241225 (merged) moved granular personal access token authorization in GraphQL from a per-field extension to the object/type level. That move dropped the traversal behavior the field extension provided: a granular token can no longer reach a child resource through its parent boundary (for example group { groupMembers }) without also holding the parent's read permission, even though the equivalent REST endpoint allows it.

Proposal

Restore traversal at the type level:

  • Inspect the fields selected on the object being authorized. When every selected field defers to an authorized, non-leaf child type, the object is reached only for traversal.
  • In that case, the granular check verifies boundary visibility (read_boundary) instead of the object's own permission; the child types enforce their own permissions.
  • Reading the object's own data (scalar fields) still requires its permission. Leaf children (all-scalar types) also still require the parent permission, because an empty collection would otherwise bypass authorization.
  • Resolve abstract (interface/union) return types to their concrete implementers.

Also remove the now-unused traversal: GraphQL directive argument and its helper plumbing.

Implemented in !242976 (closed).

Related to #601728 (closed).