Access token is the identity proof issued by IdP so that anyone in possession of the access token can access the protected user resources hosted by IdP. Therefore, developers should prevent this access token from disclosure. The app secret is a confidential information, which is only shared between RP and IdP. The app secret allows IdP to determine the identity of the RP app. Code is also a confidential information, and is used to exchange access token. Developers should prevent access token, code, app secret from disclosure.
If the attacker can obtain the access token (or code), then he can harvest the victim’s resource hosted by IdP, and even log into RP app as the victim. If the attacker can obtain the app secret, he can pretend to be the vulnerable RP app.
If app secret is disclosed, developers should revoke the app secret immediately. Whenever possible, utilize HTTPS protocol to protect any OAuth-related traffic.