OAuth2: Why should we validate the `redirect_uri` when exchanging the authorization code for an access token?