How to secure the login API

Question asked by hiten.rastogi on May 21, 2018
Hi All,


During the security test of our instance our security expert asked us to secure the login API


as it send the username and password as it is and can be used by attacker to forge the request login if the admin password is known.


Can anyone tell me how we can secure this API or in my case I can disable it also.




