set_local_db/set_dot_env diffs can contain secrets (connection
strings), so printing them unconditionally on every up/down leaked
credentials to stdout. Default output is now a line-count summary;
pass -v/--verbose to see the actual before/after lines.
Drop the --legacy flag: set_local_db and toggle_index now run
unconditionally instead of only when -l was passed, since that was the
flag's only effect.
Fix set_dot_env writing the connection/RCC_CONNECTION line twice with
opposing polarity (once from the #docker pass, once from the #cidb
pass), which flipped it to the wrong value. Collapsed the three
separate open/read/write passes into one, toggling both sections and
the connection line in a single scan so the connection line is only
ever touched once.