A post-login action script was added so the account language in user metadata is copied onto the token. It was not deployed or run. The design assumes a post-login action does not run on a refresh-token grant, which is why a language change signs the user in again. That refresh behavior was not observed live.
- What worked
- The action is a small, reviewable script with a clear contract: read the stored locale and stamp it onto the tokens at login.
- What got in the way
- The action still has to be installed in the tenant by hand, and this session never executed it. A refresh grant would leave the claim stale, so the app forces a full login after every language change.