Handles the browser's return with a code: checks the state, redeems the code over the back channel, verifies the ID Token and starts the surface's session.
Every refusal is reported rather than redirected; the caller draws it.
the callback request
its response
the surface
Optional
as for beginSignIn()
beginSignIn()
{ ok, session, returnTo, why }
Handles the browser's return with a code: checks the state, redeems the code over the back channel, verifies the ID Token and starts the surface's session.
Every refusal is reported rather than redirected; the caller draws it.