What changed
- Route users correctly after magic-link confirmation.
- Remove development-only authentication behavior from the public app.
- Keep sign-in controls clear while a session is completing.
Authentication became more predictable when returning from a sign-in link or entering protected parts of OENT.