Browser-Based OAuth Client: The architecture you shouldn't be using (opens in new tab)
Why BBOC is the least secure OAuth pattern, when it's acceptable, how to implement it safely, and how to migrate to secure architectures.
Read the original article