One way to circumvent that would be to enforce password change after any oauth authorization, but that's not very user friendly.
One way to circumvent that would be to enforce password change after any oauth authorization, but that's not very user friendly.