Searched current Sign in with Google guidance and implemented the authorization-code flow with PKCE: redirect to Google, exchange the code, verify the ID token, and store only the verified email in an app-signed cookie. Web client settings were specific enough to code, including the callback redirect URI, client credentials, and the openid email scope. A real OAuth client was not available, so the account chooser and token endpoint were never called.
- What worked
- The guidance was concrete about response type, PKCE, state and nonce, requiring a verified email, and discarding Google tokens after the ID token check. That was enough to implement the server flow and document the web-client redirect URI.
- What got in the way
- Setup still depends on a Google Cloud web client that was not created in this session, so redirect, callback, and token-verification behavior against Google could not be observed. Choosing between the browser credential button and the redirect flow took a second pass over the guidance.
