- Register validates redirect_uris/grant_types/response_types/auth-method in PHP's exact order, strips control characters and caps client_name at 255 runes, and generates client_id/secret via crypto/rand base64url - confidential clients return the raw secret once; only its sha256 hex persists (constant-time-comparable fixed transform) - sweep-unconsented, the atomic cap check and the create all run inside one wristband.Backend.WithinTx transaction (T-08-DCR-FLOOD) - 64 KiB body bound via http.MaxBytesReader collapses to the endpoint's native invalid_client_metadata body, matching D-21
10 KiB
10 KiB