Request openid email profile, use client_secret_post, surface OIDC errors on /login, and expose a no-auth diagnostics endpoint so operators can verify the running container sees AUTH_OIDC_* and the callback URL.