Why is matching hosts crucial for redirect_uri in OAuth app development?

xss.png

test