This blog post discusses the Browser-Based OAuth Client (BBOC), explaining why it is considered the least secure OAuth pattern, under which circumstances its use may be acceptable, and providing guidance on how to implement it safely as well as how to transition to more secure authentication architectures.