chris-langager/Angular-Express-Train-Seed

Plain text username and password

Opened this issue · 1 comments

It looks like the client is passing the username and password in clear/plain text in the headers. Anyone who can perform Man-in-the-middle attack can capture client identity.

To be more safe use HTTPS.