After you click on a search result and are served a webpage not owned by Google, Google can't control what happens if you press the refresh button.
A sophisticated enough client user would still have access to the all data associated to the API user.
It's not really a bug though. It sounds like DS shows a dashboard for the user absent an instruction to show a different page. That's a reasonable default.
>A sophisticated enough client user would still have access to the all data associated to the API user.
If you use one account to access an API then of course it's your responsibility to control access. How would the API provider be able to do that?
So the view may be designed by the client, but it's not hosted by the client. It's hosted on DocuSign.
Then View 2, is the "dashboard" view which of course isn't designed by the client.
In an ideally designed embedded View 1, it should not be possible to get to DocuSign's "dashboard" (View 2). Sessions should be tracked in DocuSign's API and View 1 refreshes should return the user to hosted View 1 or should return an error.