f96a0db769
After changePassword the API issues a new JWT with mustChangePassword=false. The server action now reads Set-Cookie from the API response and sets it in the browser so the middleware sees the updated flag and allows /dashboard. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>