getRestClient
Returns an authenticated client for the current user or starts login when no persisted account is current. If the current account cannot produce a valid user and client, removes that exact corrupt account and completes the normal logout, account-switching, or login flow without invoking restClientCallback.
Called from SalesforceActivityDelegate.onResume(), so this is on the Activity-resume hot path; it goes through clientManager rather than constructing a ClientManager directly so repeated resumes for the same current user reuse the cached instance instead of re-resolving the account via AccountManager on every resume. Passes the already- built user into ClientManager's package-private UserAccount-accepting peekRestClient overload (via the module- internal peekRestClientWithResolvedUser bridge in ClientManagerInternal.kt) rather than its public no-arg overload, which would otherwise re-decrypt a second UserAccount from the same Account on every call.