f6ddd89692
Desktop opens /auth/native/authorize without naming a provider. The empty-provider auto-select filtered password providers out of the candidate set, so a deployment with one OAuth provider plus username/password went straight to OAuth and never offered the password option — even though native sign-in brokers password providers through /login since56f1afc834. The filter's rationale ("a password provider can never be the target of the native flow",ed5e17f4b8) predates that change. Render a provider chooser when more than one interactive session provider is registered. Each link re-enters the same validated authorize route with an explicit provider, so the choice never leaves the native PKCE flow. A single provider still auto-selects, and the chooser is emitted before any broker state is allocated or any cookie set. The desktop only shell-opens the authorize URL and never parses its response (apps/desktop/electron/native-oauth-login.ts), so the 200 chooser page is safe on existing desktop builds. Supersedes #101713, #76941. Co-authored-by: Gille <4317663+helix4u@users.noreply.github.com> Co-authored-by: Phuong Lambert <vmphuongit@gmail.com>