These inputs should be hidden in production
Any other inputs are used to help validate the client, run other custom actions on the server, etc...
The defaults for this will successfully login. Anything else will fail. This behavior is NOT handled by OAuth, but must be included in your middleware.