Missing User Warnings
Medium
- Confidence
- 85% confidence
- Finding
- The setup flow tells users that OAuth credentials will be saved locally, but it does not clearly warn about the sensitivity of refresh/access tokens, local compromise risk, or expected file protections. Users may proceed without understanding that these tokens can enable ongoing access to their Strava account data if copied by another process or user.
