When logging URLs the passwords that are sent as URL parameters should be masked out to not write them in clear text into the log files.