There are just so many things to keep in mind, so many ways to do things, and, especially when you go slightly out of/beyond the spec to add functionality you really care about, so many interactions with existing functionality that are just to keep in mind and think about
@Cyborus Well what I can say is that authentication and authorization, especially across services, needs a lot of flexibility, because it is just sadly not a "one usecase fits all" world