Authentication should be done through POST Request
The authentication to the server should be done through POST Request with username and password in the form fields.
GET parameters are frequently logged by the web server and could lead to innadvertently revealing the username passwords.
The same is true for authentication tokens, although if they have limited
Instead use a POST request.
assigned to issue 484
for developers https://github.com/StrangeLoopGames/Eco/issues/484