To finally close the question I will summarize what worked for me.

Making “/admin” the entry point for logged in and not logged in users:



Forward every different request to login when not logged in:





The remaining part of the question is, why is the session id appended to the url as path parameter on the very first request and how could I remove it?