Hm, yeah I think the authorization flow works correct but then the browser engine that is used somehow does not forward the request to your app context correctly.
So it could be the redirect schema your app uses. Do you have a device/simulator where you see this happen.