atproto/.changeset/weak-cycles-speak.md
Matthieu Sieben 3fa2ee3b6a
Deprecate query & fragment in DPoP proof htu claim (#3879)
* Properly validate JWK `htu` claim by enforcing URL without query or fragment

* type fix

* Return DPoP validation result from `authenticateRequest`

* Log clients using invalid "htu" claim in DPoP proof

* review comments

* fix lint

* tidy

* rename dpop result to dpop proof
2025-06-05 14:46:51 +02:00

99 B

@atproto/oauth-provider
@atproto/oauth-provider
patch

Return DPoP validation result from authenticateRequest