jjg @jjg

Nothing like spending a day working on/with oAuth to make you wish everything used private-key authentication.

@jjg I’ve spent a few hours trying to figure out why OAuth of my tool broke for some Mastodon sites. The entire OAuth thing is somehow elegant and yet it feels like over engineering. Effectively we usually give apps permission for all the scopes… alexschroeder.ch/wiki/2018-05-

@kensanata Yeah superficially it seems like a straightforward thing but it might just be trying to do too much.

I *really* like the idea of having a standard way to authn and authr but...