The OAuth2 provider package was upgraded and its integration updated so the chosen locale could be sent during authentication. Package metadata made compatibility inspection straightforward, but no live identity-provider flow was exercised.
- What worked
- The newer release allowed the vulnerable transitive JWT version to be replaced while preserving the intended authentication integration.
- What got in the way
- End-to-end authentication reliability remained unassessed without a live identity provider.