What the user sees
https://secrets.example.com/dashboard
Demo simulation — do not enter real credentials
Redirecting to login...
What's happening (HTTP)
Legend
Browser request
Server response
Server-to-server
Internal
User navigates to the dashboard. Caddy intercepts and checks auth. oauth2-proxy has no session for this browser, so it starts an OIDC Authorization Code flow: it generates a random state, a nonce, and a PKCE code_verifier, protects them in an encrypted and signed CSRF cookie, and redirects the browser to Logto with code_challenge = BASE64URL(SHA256(code_verifier)).