This release now properly allows an instance of OmniAuth::AuthenticityTokenProtection (with passed in rack-protection configuration) to be used as the request_validation_phase.
If you haven't already read the release notes for v2.0.0, you should do so.