If this is new to you, you can also include the username and password in the url:
I'm not entirely sure what the concern is to be honest. If it's tracking, this doesn't provide anything on top of query parameters e.g. ?utm_campaign=
Placing the username and password in the URL results in the same TLS-protected HTTP header as normal basic authentication:
$ curl -v https://user:pass@example.com/page
[...]
> GET /page HTTP/2
> Host: example.com
> authorization: Basic dXNlcjpwYXNz
> user-agent: curl/7.77.0
> accept: */*
>
Even over HTTP, a proxy that intentionally logs the URL accessed would not see the username and password in the initial "GET" line. It would have to go out of its way to extract it from the Authorization header, which is still present regardless of how the basic authentication was initiated.If you meant user agents logging the username and password as part of the history, I suppose you could consider that a bug but it could also be considered a feature. Presumably if you're using a URL of that form your intent is in fact to be able to link or bookmark the URL including the credentials.
And corporate proxies man in the middle everyone, because the entity that controls the proxy also controls the certificate on the computer.