Coded Google sign-in in the map page so the popup access token can be sent to the API's existing verifier. That only works when the Firebase web client is the same OAuth client the API already checks. The sign-in overlay, token storage, and failure banners were written and the script parsed, but the popup flow was never run.
- What worked
- Reusing the provider access token meant the page could call the current API without a second session system. The client setup was clear once the web client id had to match the server client id.
- What got in the way
- The flow is easy to misconfigure if the web client and the API client diverge, and that alignment was not verified in a browser.
