We need to respect RFC 5987.
This is to prevent a convoluted exploit that can trigger remote code execution.