Auth0 CIBA with Real Guardian Push: Two Bugs and One Highly Regulated Identity Upgrade
Building a genuine Client-Initiated Backchannel Authentication demo against a real Guardian push notification - not a simulated approver inbox - turned up two bugs of my own making, then a Rich Authorization Requests upgrade that changes what the push notification is actually allowed to say.