且构网

分享程序员开发的那些事...
且构网 - 分享程序员编程开发的那些事

将敏感数据作为查询字符串参数发送

更新时间:2023-02-24 09:34:45

使用HTTPS时,在发送任何HTTP流量之前建立SSL / TLS连接,因此整个请求(包括URL及其参数)将被加密,不会可读。第三方可能唯一可见的是服务器证书(因此他们可以看到主机名,但就是这样)。

When you use HTTPS, the SSL/TLS connection is established before any HTTP traffic is sent, thus the whole request (including the URL and its parameters) will be encrypted and won't be readable. The only thing that's possibly visible by a third party is the server certificate (so they could see the host name, but that's it).

浏览器的历史记录不受保护尽管某些浏览器可能有一些安全浏览选项,可能会自动删除某些HTTPS URL。这个最终取决于浏览器及其配置。

The browser's history isn't protected in any way by HTTPS as such, although some browsers may have some "safe browsing" options which would delete some HTTPS URLs automatically perhaps. This one ultimately really depends on the browser and its configuration.