immers
immers copied to clipboard
OAuth client registration issues
If a client with the same id is already registered, immers server returns 500 whereas it should return 409
Need a process to remove and replace a client. If a remote server resets their DB that domain name would never be able to connect with this immer again.
- Require proof of domain ownership (can use http-signaure like in Mastodon secure mode request verification)
- Revoke any access granted to the previous client