upvote
not as bad since the blast radius is only your chat vs. knowing your password exposes all your data.

however - agree that this is not great - espeically if chat TTL is long. someone who gets your URL can read everything you're asking (eg. by sniffing your network/accessing your browser history)

reply
You don't store your password in the URL.
reply
I store my session token in a cookie, which is even worse because it's sent with every request.
reply
It's not. The cookie only gets sent to the domains/servers you specify and is not accidentally exposed via browser history or copying a link.
reply
Not in a URL generally, and if it is the only people who can see the full URL are the receiver and the sender if HTTPS is properly enabled.
reply