enhancement
By integrating the tl-security-auth-pac4j module, the configuration option com.top_logic.base.accesscontrol.ExternalAuthentication should be activated automatically, as otherwise authentication via OpenID will be rejected.
This is actually also stored in the configuration fragment of tl-security-auth-pac4j, but is reset by other modules.
Solution
Modules that have nothing to do with authentication must not set a configuration option for com.top_logic.base.accesscontrol.ExternalAuthentication.