4 ms·
Also, the OAuth RFC does not use "MUST" for 400 response and allows some freedom in this regard: > The authorization server responds with an HTTP 400 (Bad Requ
by Croftengea 2y ago
Also, the OAuth RFC does not use "MUST" for 400 response and allows some freedom in this regard:
> The authorization server responds with an HTTP 400 (Bad Request) status code (unless specified otherwise)
https://datatracker.ietf.org/doc/html/rfc6749#section-5.2 https://datatracker.ietf.org/doc/html/rfc6749#section-5.2