The bare domain rendered Dashboard, so an anonymous visitor to the front door
was held on the spinner and then redirected to Google — the marketing page was
only reachable by knowing the /LandingPage URL.
Key the decision off appParams.token rather than the resolved auth state so it
settles synchronously, and the first paint is the landing page instead of a
spinner waiting on a bootstrap request that can only redirect them away. A
signed-in user still gets Dashboard.
Also treat auth_required on / as signed out. Reaching that branch there means a
token existed but is expired or revoked, and redirecting would trap the front
door in a login bounce.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>