2017-11-03 UTC
# oodani Although publishing other kinds of redirect URIs under the same rel would be harmless, I think. Still can't craft malicious redirect URIs, you can just point the IndieAuth server to the wrong place and probably get a 400 because the other endpoints don't know what the heck these parameters are for.