Plain text username and password
Opened this issue · 1 comments
mothupally commented
It looks like the client is passing the username and password in clear/plain text in the headers. Anyone who can perform Man-in-the-middle attack can capture client identity.
zeroows commented
To be more safe use HTTPS.