What this test does

Signs in without requesting any scope, then exchanges the code at the token endpoint. Servers that take this exchange only at the authorization endpoint, as the older specification had it, are warned rather than failed.

How it passes

The token endpoint returns HTTP 200 with me, and no access_token.

Specification
§5.3.1, §5.3.3
Needs
S107 Token endpoint is listed