Something went wrong. Try again.
my own indieAuth provider! indiko.dunkirk.sh/docs
indieauth oauth2-server
Something went wrong. Try again.
Improve OAuth 2.0/OIDC spec compliance and harden token handling master
- Redirect OAuth errors to client per RFC 6749 §4.1.2.1 after validating redirect_uri - Rotate refresh tokens on use to prevent replay attacks (RFC 6749 §10.4) - Revoke both access and refresh tokens together per RFC 7009 §2.1 - Require redirect_uri at token endpoint per RFC 6749 §4.1.3 - Add WWW-Authenticate headers to 401 responses per RFC 6750 - Add sub and username to token introspection response
Author avycado13 Committer Tangled Date (Feb 17, 2026, 1:37 AM UTC) Commit e03aeaf8 e03aeaf8c9ad003ff2e7fa80d64b82ec790350f1 Parent 77b8d838 77b8d8380c338278bee8e639834cd2e985a8c4be