3 ms·
there's no way to log out, the browser has to store it instead of a session cookie which can be invalidated if it's stolen. plus what's in this comment https:/
by cp9 7y ago
there's no way to log out, the browser has to store it instead of a session cookie which can be invalidated if it's stolen.
plus what's in this comment https://security.stackexchange.com/questions/988/is-basic-auth-secure-if-done-over-https#comment209113_17216 https://security.stackexchange.com/questions/988/is-basic-au...
- thekyle 7y agoThanks, I didn't realize that the password was re-sent for every request to the site.