not sure if this would work in the manifest.toml:
(if mobilizon really has a need? webdav?)
[install.protect_against_basic_auth_spoofing]
ask.en = "Block all basic auth comming from clients (not SSO generated) ?"
help.en = "May have to be disabled for WebDav/CalDav clients, not for "randomized" ICS/webcal download links."
type = "bool"
default = nil
And for making the SSO work: SSO: still default pw injection & apps that use email as login broken?