And test to make sure the wrong user is not selected.
Ready to expand in the next commit.
We were just logging in any user without password or other verification before. Now we verify the Keycloak signature and know that the person is indeed logged in.