To the best of my knowledge (and experience), OAuth 2.0 authentication procedure displays a consent-page to user, requiring them to manually approve app-access
OAuth 2.0