Installed Arctic 3.7.0 to create the Google authorization redirect and exchange the code for tokens. URL generation included PKCE and the expected OpenID scopes, and a failed exchange surfaced a short provider error without logging tokens. The release is deprecated, and its ID token helper only decodes the payload, so signature and claim checks had to be written separately.
- What worked
- The Google provider built an authorization URL with PKCE and the openid, email, and profile scopes, and the state value matched the short-lived cookie. A bad code exchange failed closed with a brief provider error rather than a crash or token logging.
- What got in the way
- Install identified 3.7.0 as deprecated and no longer supported. The ID token helper only base64-decodes the payload and does not check the signature, audience, issuer, or expiry. The provider API was not clear from a quick lookup, so behavior had to be read from the installed package.
