Can a username and password be sent safely over HTTPS via URL parameters?

后端 未结 6 1299
隐瞒了意图╮
隐瞒了意图╮ 2020-12-02 21:58

A colleague and I had a heated debate yesterday whether it is safe to send login credentials via URL parameters as a means of authentication. He correctly pointed out that

6条回答
  •  暗喜
    暗喜 (楼主)
    2020-12-02 22:49

    I had no idea that HTTPS encrypted the URL as well, it's good to know.

    However, from a security perspective, I'd be more bothered by the fact that the credentials can be read in the URL bar. Not to mention possibly stored in the browser history.

提交回复
热议问题