
Your Auth Server Now Fetches URLs Strangers Pick
Every OAuth client you have ever built began with a small act of bureaucracy. A human opened a developer console, clicked “Register New Application,” and received a client_id. That string is now a row in a database you don’t own, on a server you’ll never see, maintained by people you’ll never meet. It is proof of identity for exactly one reason: somebody wrote your name down in advance. This act is known as client pre-registration. ...
