2020-11-19 UTC
# [Simon_Willison] Also, does this mean that it wouldn’t be safe for me to deploy my own indentity provider implementation to Glitch since all Glitch apps share the same domain? If I deployed an identity provider at `simon-indieauth.glitch.me` then someone else could deploy `evil-indieauth.glitch.me` and return a `"me"` value of `simon-indieauth.glitch.me` from it, stealing my identity