Remix.run Logo
▲ wtetzner an hour ago

You don't store your password in the URL.

▲someonebaggy an hour ago | parent [-]

I store my session token in a cookie, which is even worse because it's sent with every request.

▲SahAssar 32 minutes ago | parent | next [-]

It's not. The cookie only gets sent to the domains/servers you specify and is not accidentally exposed via browser history or copying a link.

▲bsharper 35 minutes ago | parent | prev [-]

Not in a URL generally, and if it is the only people who can see the full URL are the receiver and the sender if HTTPS is properly enabled.