If session_token is set and session_last_seen is within the last hour,
the incoming login is rejected with a clear message. Stale sessions
(idle > 1 h) and explicit logouts (token = NULL via back.php) still allow
re-login normally.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>