Can a username and password be sent safely over HTTPS via URL parameters?

后端 未结 6 1290
隐瞒了意图╮
隐瞒了意图╮ 2020-12-02 21:58

A colleague and I had a heated debate yesterday whether it is safe to send login credentials via URL parameters as a means of authentication. He correctly pointed out that

6条回答
  •  臣服心动
    2020-12-02 23:03

    As far as the transmission of the credentials are concerned, he is right. But there are many other things to consider, like brwser history, server logfiles, users watching the screen etc. which would be a risk in that case.

提交回复
热议问题