AnsweredAssumed Answered

Bug or Issue: Rest API Apache Logs Auto Login with URL

Question asked by pavan agrawal on Sep 11, 2015
Hi,

We are allowing to someone to login from REST API. So we have created username & password for them. Today when i looking apache logs then there i can see full request like service/v4/rest.php?rest_data={all parameter with username, password(encrypted)}

Once i click this URL from browser i can login in sugar, this should not be.

Is it bug or issue with sugarcrm ?

Outcomes