pub fn pkce_pair() -> PkcePairExpand description
Generate a PKCE pair. The verifier is 256 bits of CSPRNG entropy (two v4
UUIDs, as uuid draws from the OS RNG) base64url-encoded — well within the
43–128 char range, charset-safe. Challenge uses S256 (never plain).