- app.js init(): use native fetch (no Bearer) to call /api/install/status
and /api/settings/settings, so site_name loads even before login
state is confirmed; call Auth.reset() if logged but no site_name set
- auth.js: add reset() method that clears TK/US without redirecting
- app.js route(): remove early return for uninstalled; let install check
run first so init() can fall through to normal routing when installed
- app.js renderMain(): catch 401/login errors from page render, clear
Auth state, show login prompt with button that redirects back after
login (target hash preserved)