21a56dce50
Both view routes did server-side auth via req.user, but this app's auth-token is a header set by client JS (localStorage), not a cookie — so req.user is undefined on a browser navigation. permission.byGroup(undefined,...) throws status 401, and the middleware.auth gate on /vault threw Auth.errors.login() (401) for the same reason. Both routes now render the shell unconditionally (like /users, /directory) and gate client-side. conf.ejs already called app.auth.forceLogin; vault.ejs now derives isAdmin + personal namespace from /api/user/me after forceLogin instead of server-rendering them. /api/conf and /api/vault still enforce app_sso_admin + OpenBao scope server-side — only the view-route gating moved client-side where the session lives. Also removed a dead duplicate /conf route. Co-authored-by: Claude <noreply@anthropic.com>