Why do we need to pass grant type from client application when using oauth protocol?.
Sometimes, when I use wrong grant type, it says that incorrect grant type, so if I can pass only the supported value, then passing this value is redundant. The server can simply pick the supported one. The client application shouldn't have to pass it.
If more than one grant types are available for client application to pass, then can't the client simply pass the least restrictive grant type?. Why should the client care about what is the most appropriate grant type. Does the client have to comply with some standards or legal issues?.