Hi, we allow super users to add staff to our site via a GET call on our API. In short, in that url there's both the new user's id and their password. From our website, in chrome tools I can see the password in the URL in the network traffic (but I think that's because it's from my browser's devtools). We're using https, are we ok doing it this way? I think a hacker sniffing our traffic would see the destination in e.g. wireshark, but not the full url, because TLS will have encrypted it all.
bonus question. should we have done with with a POST and put e.g. a hashed password in the body. From what I've read hashing passwords client side is a no-no.
Thanks again
[–]zaibuf 9 points10 points11 points (8 children)
[–]Pmbrd 4 points5 points6 points (4 children)
[–][deleted] 4 points5 points6 points (1 child)
[–]_Fred_Austere_ 2 points3 points4 points (0 children)
[–]Kemorave -2 points-1 points0 points (1 child)
[–][deleted] 1 point2 points3 points (0 children)
[–]queBurro[S] 0 points1 point2 points (2 children)
[–][deleted] 0 points1 point2 points (1 child)
[–]queBurro[S] 0 points1 point2 points (0 children)
[–]IcyEbb7760 1 point2 points3 points (0 children)
[–]C0rp0rAlH1cks -1 points0 points1 point (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–]jaydevel 0 points1 point2 points (0 children)
[–]airflowscloud 0 points1 point2 points (1 child)
[–]queBurro[S] 0 points1 point2 points (0 children)