-
Task
-
Resolution: Unresolved
-
Medium
-
None
-
None
-
None
-
true
Putting credentials in request parameters is likely to lead to those credentials being logged in access logs. Also, there are existing decent alternatives such as Basic Auth so there is absolutely no need to keep the old and insecure os_* parameters around.
- causes
-
JRACLOUD-65287 The the os_username parameter has been blocked but it is still used in the users onboarding notifications
- Closed
- is related to
-
SER-199 Make support for os_username and os_password as url parameters require opting in
- RESOLVED