/api/auth/status did not expose whether the auth cookie corresponds to a valid dashboard session, so /login could only detect "auth disabled" (requireLogin === false) and not "already logged in". Add authenticated to the status response and redirect from /login when it's true.
1.9 KiB
1.9 KiB