- Server.Authorize ports OAuthAuthorizeController::authorize's exact validation order: usable client, exact redirect, response_type=code, code_challenge_method=S256, challenge length, scope parsing/ceiling truncation, resource check, then opaque pending-request creation - Unknown client/unregistered redirect are local text/plain 400s with no Location; every later failure is an ordered RFC3986 redirect with error/error_description/iss[/state], built via a dedicated encoder (never url.Values.Encode, which sorts keys and space-encodes as '+') - Options gains Resource and PendingRequestTTL (both PHP-parity defaults) so authorize's resource check and 600s pending expiry are configurable
25 KiB
25 KiB