Since tOS uses Keycloak as sole auth provider, the intermediate login page with the manual "Mit Keycloak anmelden" button was unnecessary. Now unauthenticated users are redirected directly to Keycloak. The error UI with retry button is preserved for failed auth attempts (expired session, unauthorized). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>