new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

Better Auth · Plugins · all subjects

oauth-provider/flow

2 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

OAuth Authorization Endpoint - Details

OAuth 2.1 authorization endpoint is the entry point for initiating OAuth flows. Only response_type: "code" is supported. code_challenge_method: "plain" is not supported due to security vulnerability. All authorization responses include iss parameter for issuer validation (RFC 9207). Clients should send state value to mitigate CSRF attacks. Code challenges derived from code verifier prevent authorization code interception via PKCE.

OAuth Token Endpoint - Supported Grants

Token endpoint supports three grants: authorization_code grant enables clients to obtain user access tokens and optionally refresh tokens with offline_access scope, client_credentials grant enables machines to obtain access tokens, refresh_token grant enables clients to update access token without user login. Current implementation issues new refresh token for every refresh request.

Give your agent this brain