Whew that was a lot for a Sunday afternoon: Implementing the usage of Access Grants for OAuth in @hollo
It's not done yet, but it's showing promise.
Whew that was a lot for a Sunday afternoon: Implementing the usage of Access Grants for OAuth in @hollo
It's not done yet, but it's showing promise.
Previously @hollo used cryptography for authorization codes and access tokens, this had some implications such as preventing us from implementing PKCE, which requires state to be tracked between the authorize screen and the authorization code token exchange.
So this paves the path to supporting PKCE in Hollo.
If you have a fediverse account, you can quote this note from your own instance. Search https://hachyderm.io/users/thisismissem/statuses/114134645480721453 on your instance and quote it. (Note that quoting is not supported in Mastodon.)