@trwnh This is feedback from @rinsuki

Is it correct that client_secret is required in /oauth/authorize?
QT: mstdn.rinsuki.net/@rinsuki/103

/oauth/authorize に client_secret が必須になってるのおかしくね? https://docs.joinmastodon.org/methods/apps/oauth#authorize-a-user

yes. otherwise, anyone could claim to be your client with only client_id.

ah, i misread -- it is indeed a mistake. client_secret is secret and should not be provided to the user during /oauth/authorize. it has been fixed. thank you for bringing it to my attention!

to be clear, client_secret is only needed when obtaining a token with /oauth/token

or when revoking a token as well. it is not needed for obtaining an authorization code.

