pub fn same_issuer(discovered: &str, expected: &str) -> Result<()>Expand description
Refuse a re-discovered issuer that is not the one the grant belongs to.
Discovery runs again from the network on both the callback and the refresh path, and the token endpoint comes out of THAT document. Every discovery check is internally consistent, so a hostile pair of documents satisfies all of them; only this comparison notices that the pair describes a different authorization server than the one that issued the grant.
A free function so it is reachable from a test. The refresh path’s copy was written inline, and deleting it — the single most serious defect found in this branch, on the path that carries the REFRESH TOKEN — passed every test.