No, we aren’t forcing developers to do anything.
By scraping the HTML you’re violating the procedure of OAuth. Any access token you negotiate this way is suspect and invalid.
The purpose of the PIN code is clear – don’t circumvent it.
There are alternatives to the PIN code flow – such as callback-based OAuth or the permission-requiring xAuth. There’s absolutely no excuse for scraping the PIN from HTML.