Add structural validation for deserialized sessionStorage data before restoring admin tokens, and validate returnPath through existing isValidReturnToPath utility to prevent navigation to excluded routes. https://claude.ai/code/session_01CmAwvNXPqD3j1od8vro8pA