usnistgov / SpectrumBrowser

ITL
12 stars 11 forks source link

Move password to body of message for authentication. #154

Closed ranganathanm closed 9 years ago

ranganathanm commented 9 years ago

The access log of the web server will include the URL of the request. Therefore, you cannot put the password in as part of the URL. The authentication url includes the password currently. This is a security issue.

jkubNTIA commented 9 years ago

This is fixed with the JSON data now storing the password