I'm building a REST API and I am in doubt about the way the password's sent is safe?
The password is sent in the URL like this:
https://www.example.com/api-version/user-name/password/
I'm building a REST API and I am in doubt about the way the password's sent is safe?
The password is sent in the URL like this:
https://www.example.com/api-version/user-name/password/
Yeah. Don't do that. Either use HTTP Basic authentication, or pass an access token such as an OAuth token as a parameter, i.e.
http://www.example.com/api-version/end-point/?access_token=...
Send it in POST payload (not in URL!) over SSL encrypted connection. Sending password as you suggested is extremely insecure.