2020-03-05 UTC
#
[tantek] re: OAuth2 spec, yeah there's definitely some sort of antipattern there where the spec was/is deliberately ambiguous enough to either cause or encourage divergent implementations where a server A may interop with clients J,K, but J,K do not interop with server B which OTOH interops with clients L,M which also do not interop with server A
