Friday, 2019-06-28

AbhishekHi All.. while using /v3/auth/tokens api, can we encrypt and pass the password field in the api?13:55
Abhishekcoz i see that when logging in with browser, the userid & password fields can be seen using developer tools page13:56
Abhishekisn't it a low security risk..13:56
fungiwhat would you encrypt it with?14:04
fungianyway, probably more of a question for the #openstack-keystone channel first14:04
fungibut dolphm's blog post from when keystone first introduced fernet tokens explains the situation fairly well, i think:
