My post about leaking information as default, is now used as reference by ! developers about how not to do Rest API.

#26925 - [4.0] Current Api authentication is harmful to security

Other CMS use WordPress to not do the same errors.

