Open
Description
It seems it's fully optional right now:
node-oauth2-server/lib/grant-types/authorization-code-grant-type.js
Lines 122 to 144 in c993eb5
Could be great if there's an option to force it. Of course one can block the request manually by checking the query, though.