Something went wrong. Try again.
my own indieAuth provider! indiko.dunkirk.sh/docs
indieauth oauth2-server
Something went wrong. Try again.
fix: authenticate confidential clients on the device grant master
RFC 8628 §3.1 and §3.4 apply RFC 6749 §3.2.1 client authentication to the device authorization request and to device_code polling. A DCR-registered client is confidential on every grant, so knowing its client_id was enough to open a device flow under its name and poll out the resulting token. Also stores registered grant_types so redirect_uris is only required from clients that redirect, and the registration response echoes what was actually registered instead of a hardcoded pair.
Author Kieran Klukas Date (Aug 13, 2026, 3:39 AM UTC) Commit a0dc928f a0dc928f82ab6d81cb303f466847d5bd1cb20bb9 Parent 090635fc 090635fc6c3120e78d54c5c198a41d7364fbbe31