my own indieAuth provider! indiko.dunkirk.sh/docs
indieauth oauth2-server

security: harden OAuth/OIDC token handling master

Make refresh token rotation atomic (UPDATE ... WHERE rotated = 0) so concurrent refreshes can't both win — the loser now triggers family revocation per RFC 9700 §4.14.2 instead of silently issuing a second valid token pair. Require client_id on the device_code grant (RFC 8628 §3.4) and verify client_secret for pre-registered clients, so device codes are bound to their originating client. Use the stable canonical profile URL (/u/username) as the OIDC sub claim instead of the user-mutable website URL, per OIDC Core §8. Add at_hash to ID tokens so RPs can bind them to access tokens. Use random UUIDs for signing key IDs instead of millisecond timestamps. Remove duplicated refresh_token response block. 💘 Generated with Crush Assisted-by: Crush:kimi-k3


+66 -11
2 changed files