The scenario is simple:
- A Rails API-only server with a Doorkeeper provider
- A mobile app and a SPA (let's say React) with users that want to be registered and logged in using email and password
When you have a normal Rails Stack, you need to define an authorizeUrl where users are redirected to provide their credentials and return to the Web/Mobile App with an authorizationCode. In API mode basically your 'authorizeUrl' is located inside the same app.
What's the appropriated way to handle OAuth flow when your provider can't serve a login page (because is an API-only server)