RequestExtend left the hint empty and relied on the daemon's
GetLoginHint fallback. That fallback reads the per-profile state file
from the calling process's user config dir, so the root-owned daemon
looks under /root/.config/netbird and never finds the file the UI wrote
under the user's own config dir. Every session extend therefore went out
without a login_hint, leaving the IdP to guess the account.
Resolve it in the UI instead, which runs as the logged-in user and
already reads the same file for Profiles.List. Mirrors what the CLI's
extend path does.