yes, you are correct and I see now where you're going with this. When a username/password pair is provided it will likely not match as an XOAUTH2 bearer token. It probably makes sense to remove XOAUTH2 from the whole auto-discovery process.
Originally posted by @wneessen in #410 (reply in thread)