Use a Cryptographically Sealed Value to Protect Against Replay Attacks Read more about Use a Cryptographically Sealed Value to Protect Against Replay Attacks
Never Send Sensitive Parameters Using a GET Read more about Never Send Sensitive Parameters Using a GET