Jun 15, 2021
The POST has to be made from your server, otherwise you expose the secret key. This is never mentioned in OAuth docs unfortunately, but needs to be done. An example would be here: https://medium.com/shriram-navaratnalingam/authentication-using-github-oauth-2-0-with-nodejs-be1091ce10a7