pub async fn start(
runtime: &OauthRuntime,
http: &Client,
pool: &SqlitePool,
subject: &str,
now: i64,
) -> Result<StartedLogin>Expand description
Begin a login for whatever the user typed.
The identity is resolved before anything is pushed to an authorization server, because the PDS we discover from is the one the resolved DID names. Starting from a handle and trusting a server to tell us whose it is would be the whole attack.