An OAuth authorisation URL containing a space around the S256 method no longer interrupts an otherwise valid connection. Only S256 is accepted. Missing or alternative methods and malformed challenges are rejected. Exact registered redirects, matching verifiers, verified-email permissions and one-time authorisation codes remain enforced.
This focused API security-control repair was reproduced and tested through the OAuth lifecycle and HTTP routes, the full release review and a verified encrypted backup. The API service and public security source were updated. The B2B transition remains switched off; the existing homepage build remains in place.