Document missing OAuth2 features and security improvements:
- State parameter for CSRF protection
- PKCE implementation
- Refresh tokens and expiration handling
- SSO logout with Authentik
- Redirect after login
- RBAC middleware
- Session timeout warnings
- Auto-refresh mechanisms
Organized by priority with code examples and references.