2022-07-21 UTC
# vikanezrimaya I just had a small epiphany about IndieAuth. 1) client_id is always fetched to check redirect_uri; 2) identity provider is allowed to reject any scopes it doesn't like whenever it wants to; 3) IndieAuth allows one to define custom scopes. Ergo, I could make a restricted scope only available to certain clients