Hacker News new | ask | show | jobs
by thayne 838 days ago
The browser could hide the secret after it is entered.
1 comments

Yeah, and it would still be useful for queries that never appear in the URL bar (like EventSource and WebSocket, where setting an Authorization header is not something that’s exposed by the browser)