Usually in REST APIs the auth token is passed via some HTTP header.
Usually in REST APIs the auth token is passed via some HTTP header.
Having them in the query params was intended for sharing indeed. I wouldn't expect someone using it on the frontend of course. I might switch to having them in the headers instead, as it was initially like that. Idea was to use the service with minimal requirements.
Tokens can be set as READ_ONLY, these tokens are only meant to be used with GET requests. So you can share the link to use in some other app for example. Again, headers might be better however we can't share them, i.e. simple copy paste.
https://stackoverflow.com/a/499594
I don't think proxy servers or sniffers see GET data - it's encrypted, assuming HTTPS of course. Server logs might be an issue. Browser logs and accidentally sharing is definitely a bigger issue. Less of a concern if API is only used behind the scenes by apps though.
Disclaimer: I'm not an auth expert!
Proxies with MITM (mostly corporate) would see everything, because they are terminating client SSL/TLS.
Yes, headers or even as a data in the POST request.
> Simply, user can accidentally send the link with token in chat, etc.
Yep! Even more - it can be seen in the URL even if the user send a screenshot.
Just hit F12 in you browser, switch to the Network tab and look what happens when you do the things.
TL;DR: no, but you should be vary of how things are logged and/or shared.
Eg: you see a screenshot with https://bank.com/pay.php?from=17255252&to=6445675665&amount=... URL in the browser...