2014年12月16日 - RESTful web services should use session-based authentication, either by establishing a ... apiKey=a53f435643de32 (transaction not protected by TLS; API Key in URL) ...
www.owasp.org