To answer your last question, eBPF XDP which is what I use can only do PASS, DROP or REDIRECT. So I stick with the easiest possible outcome and do PASS/DROP, which means your connections will just stop working.
However you can always set up the detection yourself by adding the captive portal detection pages to your wag MFA list then the browser should do everything else for you.
Unfortunately doing interception or acting like a proxy isnt something Im looking to do with wag (which makes authorisation timeout/logout a bit easier to deal with)
Hope that answers things!