Built the login and callback routes on the existing full-stack framework setup, reusing server hooks, layout gating, session cookies, and password-login handling. Framework routing, redirects, cookies, and server load behavior worked with minor friction.
- What worked
- Existing session, request hook, and protected layout patterns made OAuth a second credential path rather than a new auth system.