Clarify that client credentials are not passed in the URL

The term "query parameters" suggested that the credentials are passed in the URL which is insecure and is actually not true as the credentials are passed in the request body. See

diff --git a/oauth2.go b/oauth2.go
index 1e8e1b7..3de6331 100644
--- a/oauth2.go
+++ b/oauth2.go
@@ -31,7 +31,7 @@
 // which doesn't support the HTTP Basic authentication
 // scheme to authenticate with the authorization server.
 // Once a server is registered, credentials (client_id and client_secret)
-// will be passed as query parameters rather than being present
+// will be passed as parameters in the request body rather than being present
 // in the Authorization header.
 // See for background.
 func RegisterBrokenAuthHeaderProvider(tokenURL string) {