Password visible in network tab for request to `signUp.email`
Hello,
I'm using Better Auth in tandem with Next.js and react-hook-form and I'm seeing that the password is a raw string in the request body, like in the attached image. Is this a concern? It seems like it could be a problem, but there's nothing in the docs about it so I'm wondering if this is an issue I should spend time on.
This is the relevant code, if that helps:
data:image/s3,"s3://crabby-images/f5745/f5745b02aaf667644d360b0725b798413bf76200" alt="No description"
Solution:Jump to solution
Not a problem at all, the server will take that password and hash it and stored it encrypted, have a look at any other sign in form the network tab is a log for that page of all requests made once the tab is reloaded the log is cleared.
3 Replies
Solution
Not a problem at all, the server will take that password and hash it and stored it encrypted, have a look at any other sign in form the network tab is a log for that page of all requests made once the tab is reloaded the log is cleared.
How are you supposed to tell the server what password your trying to use?
If you are using HTTPS:// (in development http is fine) the body will not be visible in transit so no-one can intercept your request and view the body only the server and browser can
Gotcha, just wanted to double check since the only other projects I've worked on haven't used email and password auth. Thanks!