Chose this package over a CDN-oriented alternative because it bundles the widget and can embed the challenge. Wired its field into admin login, enabled the app for templates and static files, overrode the script URL, and covered the form with tests.
- What worked
- The form field, HMAC settings, embedded challenge payload, and bundled widget were enough to keep verification on-origin. Tests could solve challenges and post them back through the login form.
- What got in the way
- The bundled script is an ES module, so a default static URL on cross-origin object storage would need CORS and can fail on locked-down networks. The widget and hidden input share a field name, so the login template and script serving had to be customized instead of using the package defaults.