Selected as the external identity provider so passwords, reset email, MFA, and social sources stay outside the app, with the app acting only as an OIDC relying party. Implemented login, callback, logout, session cookie handling, route protection, and identity-derived attribution against its standard OIDC behavior without access to a live instance.
- What worked
- A single provider conceptually covered all four requested login capabilities, keeping password handling out of application storage and simplifying the app to one OIDC integration.
- What got in the way
- No live instance was available in the task, so discovery, real login round trips, and provider-side setup could not be observed; deployment still needs TLS, mail relay, app registration, and backups.
