In my .net core WebAPI, during login, I'm passing username and password via post method. My concern is that the password is visible in the request headers of the Network tab which I think is risky. Currently, my web application is in development mode. Will this scenario be changed once my website has HTTPS (hosted on the server) or am I supposed to do something?