MB-R327
For a server-side client (which is not executed on the end-user device), the authorization server ensures that the 'authorization\_details' parameter value is from the client backend and that the user has not tampered with it. For example, by requiring the usage of pushed authorization request (PAR) or JWT-secured Authorization Request (JAR).