Earlier quoted context omitted.
The user will enter their password on the provider's site via the phone browser. It relies on the user's trust of the system browser.
I meant for a native app and you being the provider. If you don't trust the client app even oAuth won't help you preventing the client app to know the user password.
But, at least if it's implemented correctly and not maliciously, the app doesn't ever see your password.