- Server.Authorize ports OAuthAuthorizeController::authorize's exact
validation order: usable client, exact redirect, response_type=code,
code_challenge_method=S256, challenge length, scope parsing/ceiling
truncation, resource check, then opaque pending-request creation
- Unknown client/unregistered redirect are local text/plain 400s with no
Location; every later failure is an ordered RFC3986 redirect with
error/error_description/iss[/state], built via a dedicated encoder
(never url.Values.Encode, which sorts keys and space-encodes as '+')
- Options gains Resource and PendingRequestTTL (both PHP-parity defaults)
so authorize's resource check and 600s pending expiry are configurable