by jol » Thu Jul 05, 2012 11:50 am
Imho credentials on the URL are a no-go, basic authentication with SSL is totally fine, especially for REST like calls. If you want to protect credentials without SSL, one can use SCRAM or similar, but you need to be aware it protects only the password, any other communication is unprotected.
Best regards, jol
Subsonic 4.7 running on Acer H340 with LDAP authentication / Windows Home Server 2011 - Android client (3.5)