In RFC6749#setion-4.1.1 introduces redirect_uri is optional.
But above Authorization Code Flow step (A), (C), (D) and also (E) describes what redirect_uri does.
And especially step (E) describes like following..
and ensures that the redirection URI received matches the URI used to redirect the client in step (C).
So I confused when I saw section 4.1.1.
I think maybe this document not wrong, just stupid I did not understand.
Please tell me why redirect_uri
parameter is optional.
Thanks in advance.