pub async fn callback(
__arg0: State<Arc<MultiProviderAuthState>>,
__arg1: Query<CallbackQuery>,
) -> ResponseExpand description
Complete the OAuth flow after the provider redirects back.
Validates the state token, resolves the provider from the stored state, exchanges the authorization code for tokens, retrieves user info, and creates a session.
§Query parameters
code— authorization code from the provider.state— CSRF state token.
§Responses
200JSON{ access_token, refresh_token?, token_type, expires_in, provider }400— invalid state, missing parameters, or provider error.502— token exchange with the provider failed.
§Errors
Returns 400 if the state is invalid/expired, code is missing, or the provider
returned an error. Returns 502 if the token exchange or user info fetch fails.