Local-account login submit (authorization flow)
Authenticate the local account and rejoin the authorization flow.
Success never mints a JWT — it flows straight into code issuance (platform client) or the consent handle (registered third-party client), exactly where the IdP callback rejoins, and burns the single-use ls. Credential failures re-render the form with one generic message: lockout state, unknown email, and wrong password are indistinguishable (no user-enumeration response oracle), while the shared AuthService.authenticate core still increments the failed-login count and applies the lockout threshold. An account flagged must_change_password authenticates but is told to rotate via the UI first — the OAuth plane must not hand a fully-scoped token to a temporary-password principal the UI would have boxed into change-password-only.
Response
Successful Response
Changes
Changed in 1 of the 114 revisions of this API.1
- ○
endpoint added
endpoint-added
- ○