a5e33ac72b
The logout function fired a non-awaited POST /logout then immediately redirected to /login. The login page's session probe would find the cookies still valid and refresh the token, redirecting back to the app. Fix by awaiting the fetch and clearing local state before redirect.