Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The documentation explicitly recommends passing sensitive credentials in URL query parameters, including a token and, in examples elsewhere, appid/secret. Query-string secrets are commonly exposed through browser history, reverse-proxy and CDN logs, analytics systems, referrer leakage, and shared terminal history, so documenting this without warning or safer guidance increases the chance of credential compromise.
