Oracle round-4 finding: authedRequest() called the private login()
helper whenever no bearer token existed AND on 401 retry. That helper
posts to /api/v1/auth/dev-login, so any authenticated API call could
silently issue dev-login regardless of UI gating.
- authedRequest checks devLoginAllowed() (VITE_ENABLE_DEV_LOGIN !==
'false') before calling login(). When dev-login is disabled it
throws AuthRequiredError instead.
- 401 retry path gated the same way.
- New AuthRequiredError exported so callers (store, scenes) can route
unauthenticated users to the login page instead of swallowing.
- src/lib/api.test.ts: regression test 'throws AuthRequiredError
instead of silently calling /dev-login when no token'. With
VITE_ENABLE_DEV_LOGIN=false api.me() rejects with /Sign in required/
and no POST to /dev-login is observed.
30/30 unit tests green.