Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The documentation instructs users to configure long-lived access-token credentials and then demonstrates capabilities including exports, deletes, and raw API access without any caution about sensitive merchant data, destructive operations, or privacy implications. In a POS context, this can lead to accidental disclosure or modification of financial, customer, employee, and inventory data by users who are not adequately warned about the scope and sensitivity of the commands.
