An adapter, helps legacy OAuth system connect to OpenID Connect service.
To achieve design goals, this adapter HAVE TO store some sensitive information temporarily.
You MUST deploy your private adapter, instead of use a public adapter service or untrusted third party adapter service.
/{provider}/tokenProxy to provider's token endpoint. Adapter will parseemail,nameandsubfromid_token, then store them temporarily, under the keyaccess_token./{provider}/userinfo/{provider}/authorizeNot recommended. Redirect to provider's authorize endpoint. You SHOULD use your provider's authorize endpoint DIRECTLY (to hide the adapter).