I am trying to implement oauth 2.0 and I want to know out what is the best practice of identifying the user that authorize the oauth flow once the user is redirected back to