## MODIFIED Requirements ### Requirement: OAuth2/OIDC Flow The system SHALL support OAuth2/OIDC authentication via Authentik with fully configurable endpoints. #### Scenario: User login - GIVEN a user clicks the login button - WHEN the frontend redirects to Authentik authorization endpoint - THEN the redirect URI SHALL be constructed from environment-configured domains - AND the Authentik authorize URL SHALL be read from environment variables #### Scenario: Token exchange and validation - GIVEN Authentik has redirected with authorization code - WHEN the callback endpoint receives the code - THEN it exchanges the code for provider tokens at the configured token URL - AND verifies token signature using the configured JWKS URL - AND validates the issuer and audience from environment configuration ### Requirement: Session Security The system SHALL protect sessions using httpOnly cookies with environment-aware secure defaults. #### Scenario: Cookie attributes in production - GIVEN successful authentication behind Traefik with HTTPS - WHEN cookies are set - THEN access_token cookie SHALL be httpOnly - AND access_token cookie SHALL have Secure flag based on environment - AND access_token cookie SHALL have SameSite based on environment