The thing you learn in Security 102 is that you should encrypt passwords in HTTPS anyway, because so much of your middleware will assume fields aren’t secured, and will happily log them — that while from a theory standpoint, password-over-HTTPS is fine, in practice it’s a liability due to organizational issues.
You can securely send plaintext over TLS, but it’s best not to when avoidable — precisely because it’s inviting the disaster above.