A colleague and I had a heated debate yesterday whether it is safe to send login credentials via URL parameters as a means of authentication. He correctly pointed out that
The requested URL might show up in Web server logs and browser history/bookmarks which is not a good thing.