TU/e single sign-on (development)

Stands in for SURFconext. It authenticates people and issues identity tokens; it holds no notion of T-LIF roles. Reach it through a portal rather than directly — an authorization request needs a registered client and a PKCE challenge.

This service is permanent, not a placeholder. Local development and CI cannot reach TU/e SSO, so something has to issue tokens there. In production TLIF_IDP_ISSUER points at SURFconext instead and the portals do not change.