syncUserFromAuthelia() did a plain check-then-insert with no transaction, so two simultaneous first-visit requests for the same brand-new user (e.g. two tabs opened right after SSO login) could race: the second INSERT hits users.username's UNIQUE KEY, which mysqli throws on (uncaught, PHP 8.1+ default report mode) rather than returning false. Switched to INSERT ... ON DUPLICATE KEY UPDATE followed by a re-fetch by username, so the losing request updates the winner's row instead of throwing. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MGDKHiU5RJdo3dqQUDow3X