After successful authentication at the provider, an account is automatically created at docspell and the user is logged in.
The new subproject "oidc" handles all the details for working with an OpenID Connect provider (like keycloak) or only OAuth2 - only supporting the "Authorization Code Flow" for both variants.