Is there any sense in use of Authorization Code Binding To DPoP Key when client is confidential and uses PKCE?
This spec defined DPoP mechanism to bind cryptographically bind access tokens. There is also mention about authorization code binding.
But hey, do you see any sense in it? Ok, it obviously is a way to prevent authorization code injection a…