this stuff also goes directly against the original goals of oauth. it was never supposed to provide identity authentication; it was supposed to let you grant one website access to the resources you own on another
but then facebook, a chief author of oauth 2.0, decided to make "log in with facebook" a universal thing, and here we are
https://mastodon.social/@azonenberg@ioc.exchange/115697743274588456