5779f0f6c9
After a successful password change the old cookie still contained mustChangePassword=true, causing the middleware to redirect back to /change-password. Now changePassword issues a fresh session cookie. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>