v0.1.1
Released commit: 137eb5830a069bf45fb3a02c8eae95c3b2355504
Fixed
- DPoP
htuvalidation against Authorization Servers on non-default ports. The
SSRF-safe pinned HTTP client now keeps a non-default port in theHostheader,
and DPoP proof generation normalizes thehtuclaim to match: an explicit
default port (:80/:443) is dropped, non-default ports are preserved, IPv6
literals stay bracketed, and any userinfo is stripped fromhtu
(RFC 9110 §7.2, RFC 9449 §4.3).