I've seen a number of articles posted here recently that just give terrible advice when it comes to OAuth2, so I figured I'd make this so people would dick themselves over.
The reason people do this, is because they are just writing filler nonsense content in the hopes you'll click on the website. They don't care if the content is solid because they just want you to see the ads.
As for my credentials, I work for a major fintech company with part of my duties being to help developers get set up with OAuth2 in their applications.
If you aren't a lazy fuck, just read this, and the next section on decoupling. Otherwise I've summarised the important bits later on.