The existing OAuth client bundle underpinned the customized Keycloak authenticator and return-to-signature flow. Static service and route checks passed, but no live authorization-code exchange was exercised in the recorded environment.
- What worked
- It fit the Symfony security architecture already present and allowed the re-authentication behavior to be added without replacing the login stack.
- What got in the way
- Runtime interoperability with the identity provider was not observed.