So yeah, um, this is not okay. It is not discoverable and could easily leak sensitive information. Auth credentials even, seriously? Also Chrome does this too. And it is preserved across `mv` to another filesystem.https://twitter.com/gynvael/status/1077671412847046657 …
-
-
oh that's... silly
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
You don’t need to support credentials in URLs in order to support basic auth. The credentials are placed in header fields in the HTTP get request.
-
Credentials in a URI is one (perhaps the only?) standard way for supplying the contents of that header field that is cross-application.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
$ getfattr -d -m - test
user.xdg.origin.url="https://user:passwd@gynvael.coldwind.pl/"