# The public client no longer requires a code_verifier. The code exchange then succeeds # with nothing but the authorization code - which is the whole attack PKCE prevents. demo: require-pkce: false