Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 4053130
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 20, 20262026-05-20T14:24:28+00:00 2026-05-20T14:24:28+00:00

I want to add integration with a third-party service to a web application (developed

  • 0

I want to add integration with a third-party service to a web application (developed in HTML and Javascript) which targets Android / iOS (and later Windows Phone). Thus I have access to all “modern” features. This third-party service needs credentials and is controlled via GET-Parameters.
For example, a request url could look like “http://www.example.org/foo?username=user&password=1234”.

Changing the third-party service to accept hashed passwords is no option as I have no access to it.

As the user does not want to type in his username and password every time he uses the service or starts the application, I want to save his credentials somehow.

Now I wonder, what’s the best way to do so.
I know that real “security” is an illusion here but I do not want to expose the credentials to unnecessary risks by saving them the wrong way.

I already thought about several possible ways

  • Plain Cookies: The most
    straightforward way – is it “secure”
    enough in this scenario?
  • DOM-Storage:
    Any differences to cookies in this
    relationship?
  • Encrypted Cookies: The
    credentials would be encrypted, but
    you could easily find out the key
    when looking at the source code of
    the page or debugging it.

Which one should I choose? Are there any better ways?
Is bothering with encrpytion actually worth it when it can be cracked that easily?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-20T14:24:29+00:00Added an answer on May 20, 2026 at 2:24 pm

    All the ways are bad and insecure. So is sending username and password as a get param – you even run this over https?

    The way to do this usually is to not store the username/password at all, but a GUID/hash that identifies the users session, and then let that session be persisted.

    That way, even if somebody else gets access to the session, they won’t have the username/password. As part of this, people cannot change the password unless they supply the existing.

    Connect to and authenticate with the 3rd party service through a backend proxy if it absolutely needs to have username/password sent.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have developed an ASP.NET chat application. Now I want some integration with my
I have numbers in javascript from 01(int) to 09(int) and I want add 1(int)
We are building a comprehensive integration test framework in C# for our application which
We want to add scripting to a project. We are hesitating which script engine
I want to write integration application test to test the full CRUD operations. I
I want add my custom sidebar next right column all page. Please check this
I have dbml with single table users i want add partial class for User
I have a website built with ASP.NET (3.5) and want add some level of
I have a list of string values that I want add to a hashtable
I'm using FOSUserBundle to authenticate users from database and now I want add authentication

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.