Used golang.org/x/oauth2 for the authorization-code flow with PKCE and for the callback token exchange. A newer release pulled in with the first OpenID Connect install was replaced by v0.21.0 so the module graph stayed on the service's Go version. The library can probe more than one client-authentication style at the token endpoint, so the tests accepted both HTTP Basic and form credentials. The exchange succeeded on that local endpoint.
- What worked
- PKCE and the authorization-code config were enough to build the login redirect and exchange the code. The pinned release stayed compatible with the rest of the module set and the tests.
- What got in the way
- Automatic client-authentication detection can issue an extra token request, and that behavior had to be read out of the package and accommodated in tests rather than being obvious at the call site.
