Some tips:
1. Don't build your own OAuth 2 server.
And if you're just doing auth for your own apps - not providing auth services for third parties to integrate with - I wouldn't suggest using OAuth at all. It's much more complicated and you're much more likely to make mistakes.
It isn't a bad idea to (carefully) read and learn from the principles of the OAuth 2 spec in order to make your own auth services, but I'd generally suggest avoiding making an OAuth server by hand unless you are very experienced in doing this. There are a lot of silly mistakes you can make due to the over-complication.
2. Don't use passwords.
It's 2018. Passwords are really not a good way to secure your system. You're going to end up building an email-based password reset system anyway right? So just cut to the chase and use magic-link based login only. It's pretty easy to do securely.
3. Keep it simple.
If you're implementing something you don't fully understand, or think you probably understand, but haven't considered every possibility, you're likely to introduce vulnerabilities. A simple auth protocol which you fully understand will perform better than a complex one you don't understand.