pay2all / pay2all-recharge-api-document

Recharge and bill payment
10 stars 18 forks source link

API key is showing in the URL; not secure #3

Open hkchakladar opened 6 years ago

hkchakladar commented 6 years ago

The API call is using GET method, instead of POST method. The API is currently showing in the url, which is very insecure practice.

https://github.com/pay2all/pay2all-recharge-api-document/blob/master/submit.php#L27

Please use POST method for API calls.

pay2all commented 6 years ago

Dear sir,

For POST method Please click on below link

http://www.pay2all.in/developers/v1/recharge

Thanks & Regards

On Wed, Oct 3, 2018 at 3:28 PM hkchakladar notifications@github.com wrote:

The API call is using GET method, instead of POST method. The API is currently showing in the url, which is very insecure practice.

https://github.com/pay2all/pay2all-recharge-api-document/blob/master/submit.php#L27

Please use POST method for API calls.

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/pay2all/pay2all-recharge-api-document/issues/3, or mute the thread https://github.com/notifications/unsubscribe-auth/AFW13AJdmFOKQ-vY5O-WB-KHJs3lsndNks5uhIpcgaJpZM4XFreF .

-- Thanks & Regards Ceres Infotech Pvt. Ltd. +918802034056, +911165021421 www.ceresinfotech.com