- Config::load / load_with read the TOML file; port fields accept
either a TOML int or a string (real configs use both)
- empty strings resolve to defaults: db 3306, web 8080,
$HOME/.config/rpn state dir, <state>/backups backup dir; an
explicit state dir steers the backup default
- show() masks the password; validate_database() enforces
host/user/name for commands that touch the database
- resolve_config_path() implements the documented lookup order