* Properly validate JWK `htu` claim by enforcing URL without query or fragment * type fix * Return DPoP validation result from `authenticateRequest` * Log clients using invalid "htu" claim in DPoP proof * review comments * fix lint * tidy * rename dpop result to dpop proof
99 B
99 B
@atproto/oauth-provider
@atproto/oauth-provider |
---|
patch |
Return DPoP validation result from authenticateRequest