CI / ci (pull_request) Failing after 6m21s
The link in the magic-link email landed users on the JSON API endpoint /auth/verify, exposing the raw response body in the browser. The SPA already ships the wrapper page (verify.html + verify.js) — it reads the token, POSTs to /auth/verify itself, saves the JWT, and redirects to /app.html. Pointing the email at /verify.html restores the intended flow: operator clicks link → verifying… → 'Signed in as <email>' → 'Go to your notes'. Verified locally: the LogMailer now emits http://localhost:18080/verify.html?token=…, GET /verify.html returns the SPA HTML, and POST /auth/verify still returns the JWT JSON (unchanged).