Real talk, OIDC and more specifically, auth service providers (I'm looking at you Zitadel and Auth0) make security objectively worse.
The OIDC process is overly complex for most use cases, resulting in wads of excess code that is ripe for bugs. This is made worse by the atrocious documentation supplied by service providers to developers, coupled with their complete lack of meaningful support.
