Selected as managed login for a server-side web service needing password reset, MFA, and social sign-in. Implemented authorization-code flow, session cookie, and route middleware against its standard OIDC endpoints without an SDK, with offline tests using a stubbed exchanger. Local code and tests passed; live tenant configuration and real login were left for later.
- What worked
- Standard OIDC endpoints and hosted login concept mapped cleanly to server middleware with separate page redirect and API 401 behavior, and the flow was testable offline through an injectable exchanger.
- What got in the way
- No live tenant was configured and no real login, token, or userinfo call was exercised, so hosted behavior such as reset, MFA, and social connections remains unverified.