- Register validates redirect_uris/grant_types/response_types/auth-method
in PHP's exact order, strips control characters and caps client_name at
255 runes, and generates client_id/secret via crypto/rand base64url
- confidential clients return the raw secret once; only its sha256 hex
persists (constant-time-comparable fixed transform)
- sweep-unconsented, the atomic cap check and the create all run inside one
wristband.Backend.WithinTx transaction (T-08-DCR-FLOOD)
- 64 KiB body bound via http.MaxBytesReader collapses to the endpoint's
native invalid_client_metadata body, matching D-21