This PR adds new support for fine-grained control over the server/ui handling when the X-Forwarded-Prefix header is set. Additionally, this allows getting a websocket token, so cases where the websocket is not pre-authenticated, but regular requests are authenticated, it works the same. Added a new endpoint for probing for pre-authenticed conditions without causing a 401 to be logged.