Handle the SAML 2.0 callback after the user authenticates with the identity provider. Parses the SAML response, verifies the XML signature against the IdP certificate, extracts user attributes, maps groups to scopes, and optionally provisions the user via JIT.