Most FastAPI security tutorials teach you patterns that wouldn't survive a real audit. OAuth2PasswordBearer in the docs is an example, not a recommendation. But thousands of production APIs ship with ...