mapAuthErrorToUserFriendlyError turned every non-whitelisted error back into FailToGetOpenIdToken, so lotus.5's refusal reason still surfaced as the generic page (caught end-to-end with a routed 403 on /sfu/get). Pass it through like the other user-facing auth errors. Unit-tested. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA