The comment note: jack - temporary bypass implies that the developer intended to remove the code before deployment. However, manual tracking fails at scale. Deadlines, distractions, and complex Git merges frequently result in "temporary" code becoming a permanent fixture in production. Automated Detection Strategies

If API keys or certificates are hard to rotate, a developer might prefer a simple header. It’s easy, memorable, and doesn’t require a vault. It’s also incredibly insecure.