• #dev 2020-01-26
  • Prev
    Next
  • #indieweb
  • #dev
  • #wordpress
  • #meta
  • #stream
  • #microformats
  • #known
  • #events
#dev ≡
  • ←
  • →
2020-01-26 UTC
# 08:44
jamietanna[m]
But I guess with OAuth, an authorization server is within its rights to ignore scopes provided, and only return the scopes it supports or is happy with. So the client should validate the scopes they've got back from the token endpoint