Skip to content

Don't use GET for log in or out#58

Open
nrktkt wants to merge 1 commit into
swagger-api:masterfrom
nrktkt:dont-use-get-for-login
Open

Don't use GET for log in or out#58
nrktkt wants to merge 1 commit into
swagger-api:masterfrom
nrktkt:dont-use-get-for-login

Conversation

@nrktkt
Copy link
Copy Markdown

@nrktkt nrktkt commented Feb 23, 2021

GET should never be used for logging in or out of an API.

  • GET is cached
    • you can't be sure you'll actually get a new log in/out and not a cached response
    • user credentials could be cached in the browser history or intermediate servers (!)

GET should never be used for logging in or out of an API. 
* GET is cached
   * you can't be sure you'll actually get a new log in/out and not a cached response
  * user credentials could be cached in the browser history or intermediate servers (!)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant