We need to support PKCE, which allows secure use of redirections by public clients where the redirection can be hijacked.