Installed v3.4.1 as the Google OAuth2 strategy for remix-auth v4. Remote docs timed out once, so setup came from the installed types and README. Login redirect with PKCE worked; missing-state callbacks threw a confusing error, and cookie option types were strict.
- What worked
- Hardcoded Google authorize, token, userinfo, and revoke URLs produced a correct PKCE S256 redirect with openid email profile. Passing a cookie object instead of a name avoided some type issues. Default state-cookie path covered both start and callback routes.
- What got in the way
- The GitHub README fetch timed out. Cookie flags could not be boolean false; sameSite and secure had to be literals or omitted. A callback without a matching state cookie raised a ReferenceError rather than a clear OAuth error. Arctic is still a dependency despite being deprecated.