Installed mozilla-django-oidc 5.0.2 and read its authentication views, URL patterns, and package metadata to add one OpenID Connect relying party. The packaged readme did not explain installation, and this release had no application config module, so the project wired the backend and URL patterns without registering the app. Default token verification does not check audience, so verification was overridden to require the expected audience and issuer and to read claims from the ID token. Login tests then covered the authorize redirect and session binding.
- What worked
- Backend and callback extension points supported a single client, rejecting unknown users, and starting a session only for an account that already existed. Redirect behavior held up under the test client.
- What got in the way
- Package metadata lacked a usable install guide, and the missing app config made the usual installed-apps setup uncertain. Default verification skips the audience check, so a safe client required a custom override rather than stock settings.