Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The README instructs users to place long-lived Strava access tokens, refresh tokens, client ID, and client secret directly into a local JSON config without any warning about their sensitivity or guidance on file permissions, secret isolation, or rotation. If that config is exposed through backups, local compromise, logs, screenshots, or accidental commit, an attacker could access the user's Strava account data and refresh tokens to maintain access.
