yes, incorrect handling of auth by the client library
there is several libraries i'm familiar with now, applesauce from the dev of #nostrudel, the #coracle libraries (also used in #flotilla and #welshman) there is #NDK which is the one Pablo and idk who else is working on, used on highlighter and olas, and there is also fiatjaf's nostr-tools which is being used by njump, and probably others i am not familiar with
fortunately most of them now are taking getting auth right seriously, so i'm pleased to hear you found and will soon squash another bug