Used session-based route protection so the inbox and ticket routes require authentication while OAuth callbacks stay public.
- What worked
- Route inspection confirmed the auth middleware on protected routes, and guest requests redirected to login as expected.