Expand description
Fetching the JSON documents OAuth discovery depends on.
Three rules apply to every document here, and each exists because the reference client enforces it:
- No redirects. The mix-up defence compares a document’s
issueragainst the URL it was fetched from; a302would make that comparison meaningless while still appearing to pass. Seecrate::net::guarded_get_no_redirect. - Status exactly 200. Not “2xx”, not “whatever parsed”. A
204or a206is not a metadata document. - Content type must be JSON. A server answering
text/htmlis not serving the document we asked for, whatever the bytes happen to parse as.
On top of the SSRF guard and the body cap those bring with them.
Constants§
- DID_
JSON - Content types accepted for DID documents.
did+ld+jsonis whatplc.directoryactually serves. - JSON
- Content types accepted for OAuth metadata documents.
Functions§
- get_
json - Fetch a JSON document, requiring 200 and an acceptable content type.
- get_
json_ optional - As
get_json, but a404means absent rather than failed.