I mean... It sounds like he was right, in the sense that sending passwords verbatim over HTTPS is completely normal and fine.
Obviously (not) logging cleartext passwords is the kind of thing you learn in Security 101.
Obviously (not) logging cleartext passwords is the kind of thing you learn in Security 101.
You can securely send plaintext over TLS, but it’s best not to when avoidable — precisely because it’s inviting the disaster above.