When an API requires the user to authenticate, the password should be encrypt in database
When an API requires the user to authenticate, the password should be encrypt in database