...since we use https (and I'd hope that the browser would respect that boundary). Most of the page invocations are via a javascript submit and a login token is used to do some rudimentary checking for the purpose of sequencing.

But, yes I think it's a bad idea if there's not an easy out (such as a nobots type of metatag).