The origin validate ForcePKCE in server.ValidationTokenRequest func:
if s.Config.ForcePKCE && codeVer == "" {
return "", nil, errors.ErrInvalidRequest
}
Should add filter by grant type authorization code?
if gt == oauth2.AuthorizationCode && s.Config.ForcePKCE && codeVer == "" {
return "", nil, errors.ErrInvalidRequest
}