2022-03-23 UTC
# [fluffy] IndieAuth’s rules around identity collapse used to be way more liberal and were controlled at the domain level, but that leads to some pretty obvious and onerous attacks on shared domains with individualized hosting (e.g. tilde.club or academic homepages) and so that’s why we went through the whole revision with validating it based on matching endpoints.