It also lacks the option for a client to request an AUTH challenge if one has never been sent.
Maybe AUTH is only needed for write, yet a clients can’t ask for a challenge before they first write. They’d have to auth even just to read - which isn’t ideal privacy wise. Unless your relay requires auth to read - again possible.