Alright, I think we can call it. Between @tlodderstedt's OAuth Security Best Practices and OAuth 2.0 for Browser Apps, the Implicit Flow is dead.
https://tools.ietf.org/html/draft-ietf-oauth-security-topics-09
https://tools.ietf.org/html/draft-parecki-oauth-browser-based-apps-00
https://medium.com/@torsten_lodderstedt/why-you-should-stop-using-the-oauth-implicit-grant-2436ced1c926
WeChat ID
aaronpk_tv