State in OAuth2 callback should be short-lived, like session cookie, but shorter :) 1 or 5 minutes, maybe configurable.