moves the "Different Profile URLs" section from security considerations into section 5 as the final step to make it more prominent to client developers
Renames header to "Authorization Server Confirmation"
Rephrases a bunch of the content
Adds several examples of cases that the initially entered profile URL may differ from the final URL