What the user sees
https://secrets.example.com/dashboard
Demo simulation — do not enter real credentials
Redirecting to login...
What's happening (HTTP)
Legend
Browser request
Server response
Server-to-server
Internal
The app authenticates with Google via OAuth 2.0 and OpenID Connect
User navigates to the app dashboard or clicks 'Sign in with Google'. The app checks for a valid session and finds none, so it generates PKCE parameters (code_verifier + code_challenge), a random state for CSRF protection, and a nonce for token replay prevention, then redirects to Google's authorization endpoint.