Cookie max-age was 900s (15 min, matching access token) but refresh token lives 7 days — users got bounced to login after 15 min idle because the Go SSR middleware rejected the expired cookie before JS could refresh. Now cookie max-age = 604800s (7 days) on both the client (auth.js) and server (auth.go OIDC callback). Go page-auth middleware accepts expired-but-signed JWTs via new parseJWTIgnoringExpiry() so the page shell renders and the Preact SDK can refresh client-side. API middleware still validates expiry strictly. 6 new middleware tests cover strict/lenient/tampered/garbage cases. VERSION bumped to 0.6.8 (rebrand was already shipped but file missed). ROADMAP-UI.md added with 7 milestones (v0.6.9–v0.6.15). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>