Adds native OpenID Connect login alongside the existing LDAP and
forward-auth modes. Two new TA_LOGIN_AUTH_MODE values: oidc (SSO only)
and oidc_local (SSO + local break-glass), mirroring ldap/ldap_local.
TAOIDCBackend maps OIDC claims onto the Account model (USERNAME_FIELD is
name) and promotes staff/superuser from a configurable group claim, like
the LDAP backend. The redirect_uri is anchored to TA_HOST so it stays
correct behind nginx and a TLS-terminating proxy; PKCE and audience
verification are on. The login page gains a "Log in with SSO" button
driven by a public /api/user/oidc/ endpoint, hidden in oidc-only mode.
API token auth is unaffected.
Configured entirely via TA_OIDC_* env vars. Tested against Authentik.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>