The earlier dialog hardcoded window.location.hostname + port 8767 +
tls=false, which only worked for plain LAN deploys. Behind Traefik
or similar reverse proxies, the phone needs a completely different
endpoint than the dashboard URL.
Now:
* First open infers sensible defaults from the dashboard URL —
https://hermes.axiom-labs.dev defaults to the dashboard hostname
with TLS enabled on :443; plain http defaults to port 8767 with
TLS disabled.
* "Edit" reveals a Host / Port / TLS form with a live wss:// preview.
* Values persist in localStorage (hermes-relay-pair-{host,port,tls})
so subsequent opens skip the form.
* Toggling TLS auto-updates the default port (80↔443, 8767↔443)
while preserving any non-default value the operator typed in.
* Errors surface an "Edit pair URL" shortcut so a misconfigured
host can be fixed without re-navigating.
RelayManagement no longer passes host/port/tls props — the dialog
owns its config end-to-end.