+19
−1
+46
−1
+18
−0
Loading
A session that still owes forced onboarding gets 403 setup_required from every protected route, but the panel rendered it as the generic forbidden line — the one step that unlocks the app read as missing authorization. api.ts now announces the code on a window event (client module has no router) and the App shell, inside the Router, navigates to /setup; the wizard resumes from the surviving session with or without a token. Other 403s are untouched. Panel tests: +2 (fires on setup_required, silent on any other 403).