# Next.js and Electron

## Next.js (App Router)

1. Register a public client; redirect `http://localhost:3000/api/auth/callback`.
2. On `/api/auth/login` generate PKCE S256 (`navcom_oauth.pkce_s256` or `passport-navcom.pkceS256`), store verifier in an httpOnly cookie, redirect to `/oauth/authorize`.
3. Callback: `exchange_code` then `GET /oauth/v1/me`. Print or session-store `sub` and `rsi_handle`.
4. Button: copy `/static/buttons/sign-in-with-navcom.svg` (no tracking).

## Electron

Same PKCE. Redirect URI must be listed (loopback `http://127.0.0.1:<port>/callback` is simplest). Do not ship a client secret inside the asar. Public client + S256.

Default scopes remain `openid profile rsi` until the P6 scope split ships.
