76300e281f
- Truncate admin password in logs; write full password to data/auth.log (0o600) - Persist access token in sessionStorage so it survives page reloads - Simplify tryRefreshToken to use GSAP-style promise deduplication - Remove spurious POST redirect on 401 during token refresh - Guard passkey button reference in login finally block