Two invariants: (1) the full add/status/refresh/logout lifecycle through the
real credential pool against an in-process IdP on 127.0.0.1 that checks the
S256 verifier and revokes refresh tokens on rotation, including peer-rotation
adoption and a forged-state callback that never reaches the token endpoint;
(2) a token_url off the authorize host allowlist is refused before any HTTP
request on both login and refresh, and a non-https endpoint is rejected.
(cherry picked from commit 0dcf2c7c22ceae2eb847dbda15fb2c6a65ae5c3d)