Extended the existing Google token verifier so the map page can send a browser ID token on API calls, including a public config endpoint that stays unauthenticated. Verification was checked with unit tests against a mock token endpoint, not against live Google.
- What worked
- The existing verifier adapted cleanly to an extra token query parameter, and tests covered signed-in map config versus ID-token API access.
- What got in the way
- Live token issuance and Google-side verification were not observed; tests used a mock server.
