If session_token is set and session_last_seen is within the last hour, the incoming login is rejected with a clear message. Stale sessions (idle > 1 h) and explicit logouts (token = NULL via back.php) still allow re-login normally. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>