| ▲ | wtetzner an hour ago |
| You don't store your password in the URL. |
|
| ▲ | someonebaggy an hour ago | parent [-] |
| I store my session token in a cookie, which is even worse because it's sent with every request. |
| |
| ▲ | SahAssar 32 minutes ago | parent | next [-] | | It's not. The cookie only gets sent to the domains/servers you specify and is not accidentally exposed via browser history or copying a link. | |
| ▲ | bsharper 35 minutes ago | parent | prev [-] | | Not in a URL generally, and if it is the only people who can see the full URL are the receiver and the sender if HTTPS is properly enabled. |
|