Installed v4.2.0 and wired an Authenticator with cookie sessions to gate one private route. It matched Remix 2.16, unlike the newer first-party auth package. Setup needed a close read of the v4 API and a per-request authenticator so the callback origin could vary.
- What worked
- The Authenticator plus cookie session storage was enough to start Google login, store only email and name, and keep public booking routes open. Pinning the exact version fit the rest of the app.
- What got in the way
- TypeScript complained about Authenticator.use with the OAuth2 strategy until the cookie and strategy wiring were adjusted. The v4 surface is not the same as the newer Remix auth package, so the right package had to be confirmed first.
