Missing User Warnings
- Category
- Not specified by scanner
- Confidence
- 86% confidence
- Finding
The markdown states that successful registration stores two HttpOnly cookies, including a JWT and a pendingUserToken, which affects authentication state and user session handling. This is a behavior with privacy and system-integrity implications, but the document presents it as implementation detail without any caution or user-facing warning.
- Content
