Is token based authentication secure when
问题 any request is made via HTTPS and the token is transmitted the following ways: a) GET https://foo.dom/foobar?auth_token=abcxyz b) GET https://foo.dom/foobar with HTTP-header like X-FOOBAR-TOKEN: abcxyz As I understand SSL, in case of an HTTP request the client first negotiates the SSL connection and does only transmit additional parameters and/or HTTP headers in case the secure connection was established successfully. Am I right so far? Thx fur any suggestion. Felix 回答1: SSL buys you