问题:公共客户端为什么不能安全保存 client secret 在 OAuth 2.0 授权码模式(Authorization Code Grant)中,传统做法是用 client secret 来证明「换 token 的请求来自合法客户端…