Added a diagram of the discovery chain, drawn so the cross-check gets the same weight as the three hops
--- +++ @@ -7,3 +7,5 @@ **Every hop must agree with the one before it.** The identifier your metadata publishes has to be exactly the address the client connected to. If they differ, a strict client rejects the token — and nothing about that failure is visible from a status code, because every individual request looks fine. The check that actually matters is the cross-check: fetch the 401 challenge and the metadata document separately, and compare them to each other. Testing either one alone tells you nothing about whether they agree.++A client is never told your endpoints by a human. It walks a chain:
Every hop must agree with the one before it. The identifier your metadata publishes has to be exactly the address the client connected to. If they differ, a strict client rejects the token — and nothing about that failure is visible from a status code, because every individual request looks fine.
The check that actually matters is the cross-check: fetch the 401 challenge and the metadata document separately, and compare them to each other. Testing either one alone tells you nothing about whether they agree.
Captured the requirements that decide a submission: annotations, the OAuth chain, and why registration is self-service
Initial version — no prior content to diff against.
A client is never told your endpoints by a human. It walks a chain:
Every hop must agree with the one before it. The identifier your metadata publishes has to be exactly the address the client connected to. If they differ, a strict client rejects the token — and nothing about that failure is visible from a status code, because every individual request looks fine.
The check that actually matters is the cross-check: fetch the 401 challenge and the metadata document separately, and compare them to each other. Testing either one alone tells you nothing about whether they agree.