my own indieAuth provider! indiko.dunkirk.sh/docs
indieauth oauth2-server

fix: authenticate confidential clients on the device grant master

RFC 8628 §3.1 and §3.4 apply RFC 6749 §3.2.1 client authentication to the device authorization request and to device_code polling. A DCR-registered client is confidential on every grant, so knowing its client_id was enough to open a device flow under its name and poll out the resulting token. Also stores registered grant_types so redirect_uris is only required from clients that redirect, and the registration response echoes what was actually registered instead of a hardcoded pair.