The route had a redundant isAuthed() checking for 'bpb_admin' cookie, but login sets 'admin_token'. The middleware already guards all /api/admin/* routes, so the in-route check was just wrong. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Description
No description provided
Languages
TypeScript
49.5%
JavaScript
22%
HTML
12.1%
CSS
8.5%
Shell
7.2%
Other
0.7%