2022-05-29 UTC
# [dmitshur] So if I got all this right, my code requiring the incoming code_challenge to be exactly 43 (not 44) bytes is sound and matches what the IndieAuth spec requires (indirectly, via RFC7636), and I should report the bug to the other side sending me a 44-byte code_challenge with a '=' at the end.