Instead, you need to call users' default browser (Firefox, Chrome, whatever they have) and it'll return back with the token. Just like OAuth on desktop.
It's much, much safer, because the app can't see or hijack the login process - it doesn't get access to the login form and can't phish you with it.
The utter ignorance in comments here is really depressing, what happened with HN?