- Store user password hash in session during login
- Validate password hash compatibility on requests to prevent session reuse
- Revoke all user access tokens and clear session on ChangePassword
- Complete removal of completePendingOAuthBinding logic to prevent unintended account takeovers (AUTH-ROUTE-1).
- Add strict OIDC policy checks (global switch and source active states) across authorization and callback paths (AUTH-POLICY-1).
- Fix OIDC test cases to properly clear the Redis-backed system config cache using composite keys.