Description
Receiving passwords, API keys, secrets, or access tokens in URL query strings can leave those values in browser history, server access logs, proxies, caches, or Referer headers.
Potential impact
- Account passwords and tokens can be exposed through logging or monitoring systems.
- Referer headers or shared links can disclose sensitive values to third parties.
Remediation
Send sensitive values in an HTTPS request body or authentication header. Keep URLs limited to identifiers and non-sensitive filter values.
Examples
Before
csharp
[HttpGet("reset")]
public IActionResult Reset([FromQuery] string newPassword)
{
return Ok();
}
After
csharp
[HttpPost("reset")]
public IActionResult Reset([FromBody] ResetPasswordRequest request)
{
return Ok();
}
Explanation:
- Before: Reading passwords, API keys, secrets, or bearer tokens from URL query parameters can expose them through browser history, access logs, proxies, caches, and Referer headers.
- After: Receive sensitive values in an HTTPS request body or header and keep secrets out of URLs.