Security risk using token in url

Re: Security risk using token in url

por Juan Leyva -
Número de respuestas: 0
Imagen de Core developers Imagen de Moodle HQ Imagen de Plugin developers Imagen de Testers
Hi,
could you change the way the request is done so instead passing the parameters as GET it uses POST? This will enforce security (apart from using https) so web servers (or analytics tools) does not log the access tokens.