I’m not sure why you’re deadset on OAuth. If everything is under your own control you do not need it.
OAuth is a protocol designed for authentication against 3rd party auth providers not under your control. For example, I’m using what I detailed above to auth against an LDAP under my control. Why would I want to introduce an OAuth shim there?