Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The README instructs users to generate and store Douyin login cookies locally in a JSON file, but it does not warn that these cookies are effectively authentication material and should be protected like credentials. If the file is exposed through weak filesystem permissions, backups, commits, or malware, an attacker may be able to hijack the user's authenticated Douyin session.
