Validate encrypted-string fields in validateCipherEncryptedFieldsForCompatibility
before they reach storage:
- FIDO2 credentials (12 fields: 8 required + 4 optional)
- SSH key (privateKey, publicKey, keyFingerprint/fingerprint)
- Password history (password per entry)
This closes a defense gap where plaintext in these positions was silently
accepted on import and later discarded at response time.
parseBitwardenCsvFieldLines previously discarded any field line that did not
contain the ': ' delimiter, truncating multiline values like OpenSSH private
keys to only their first line.
Replace the map+filter pipeline with a reduce that accumulates continuation
lines (lines without ': ') into the previous entry's value, joined by '\n'.
This preserves the full private key content through a CSV round-trip.
Fixes: CSV export to import of SSH key items where the private key body was
silently dropped.