You're literally putting the password in plain-text into the (unencrypted) browser bookmarks (and also into your terminal where it's likely logged to your ~/.bash_history).
That is the bigger security issue you have, not how Firefox is handling the display of the URL.
If anything, Firefox is highlighting your insecure security practice.