fcd97b12aa
Host.lookUpWildcardParent() walked all labels of the host down to its own leaf and only inspected that leaf's "*" child, so it found a wildcard nested under the host (the base-domain case, e.g. *.cool.mysite.com for cool.mysite.com) but missed the common case where the wildcard is a SIBLING of the host's leftmost label (e.g. *.nl.wgnode.com covering an already-existing sso.nl.wgnode.com). The /wildcard-parent route then returned nothing and the edit form's "Parent Wildcard" option stayed greyed out, leaving no way to convert an existing auto-SSL host onto a wildcard issued afterward. Track the parent node during the walk and check the sibling "*" slot too. The never-created-subdomain case is unchanged (plain lookUp()'s wildcard fallback in the route still handles it). Sync the test mock and add regression coverage for the sibling case (existing host, never-created host via the route fallback, and a deeper-wildcard negative case). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>