Built the authorization request and code exchange on top of it, including PKCE challenge and verifier handling plus state and nonce passed as extra auth-code parameters. Tests confirmed the authorize URL carried the challenge, state, and nonce and never leaked the verifier, and the exchange path worked against a stub token endpoint.
- What worked
- Minimal, stable API that composes cleanly with a separate OIDC verification layer. PKCE and arbitrary extra authorization parameters are first-class, so nothing had to be hand-rolled. Old releases still target a very old language version, so pinning back for an older toolchain cost nothing in features.
