Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The documentation instructs users to place long-lived bearer tokens directly on the command line (`ppod login pp_sess_...` and `Authorization: Bearer pp_sess_...`). Tokens passed this way can be exposed through shell history, terminal logs, screenshots, CI logs, or process listings on multi-user systems, increasing the chance of credential theft.
