The task that one asks to me seems to me really impossible.
We use Spring, and Swagger UI to test the Back-End Spring.
We have a Rest controller with a method for the login presenting 2 parameters annotated @RequestParameter (one for the login, and the second one for the password).
@PostMapping("/login")
public JSONObject login(@RequestParam(name = "username")String username, @RequestParam(name = "password")String password ){
return null;
// controller for Swagger-UI
// managed by Spring security
}
Necessarily, we send to the server an HTTP request with the password as plaintext : https://myserveraddress:8443/MyApplication/login?password=mySecretPassword&username=myLogin
One asks me to "hide" in the URL the password, to hide the value of the parameter called password sent to the Backend server, without changing the signature of this method.
I need an advice. It seems to me impossible. I have no idea. Even by replacing @RequestParameter by @RequestHeader, the value of the password will be sent to the server (hopefully) and see. I am within inches of saying it's not possible.
Thanks a lot for your help to confirm or infirm by giving me a miraculous solution.