| ▲ | someonebaggy an hour ago | |
I store my session token in a cookie, which is even worse because it's sent with every request. | ||
| ▲ | SahAssar 30 minutes ago | parent | next [-] | |
It's not. The cookie only gets sent to the domains/servers you specify and is not accidentally exposed via browser history or copying a link. | ||
| ▲ | bsharper 33 minutes ago | parent | prev [-] | |
Not in a URL generally, and if it is the only people who can see the full URL are the receiver and the sender if HTTPS is properly enabled. | ||