f4ece4890d
client-side router.push races with Set-Cookie processing. redirect() in the server action sends cookie + redirect in one response — browser applies the new JWT before navigating, so middleware sees mustChangePassword=false. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>