5.2.2 Authorization server

The authorization server shall support the provisions specified in clause 5.2.2 of Financial-grade API - Part 1: Baseline Security Profile, with the exception that section (enforcement of RFC7636) is not required. actually refers to 5.2.2 item 7. List item numbers need to be denoted differently from actual section numbers for clarity. Perhaps 5.2.2 - 7?

