Last updated 4 years ago
Client secret cannot be protected
e.g., 在single page網頁中, 可能會把secret寫在JavaScript中
No Authorization flow involved: directly get access token