Secure flag on session cookies broke HTTP LAN access — browsers refuse to send Secure cookies over plain HTTP, causing 401 redirect loop. Fix: check X-Forwarded-Proto header. Only set Secure when request came over HTTPS. HTTP on LAN works, HTTPS still gets Secure cookies. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>