With this update, users can no longer log in to Salesforce by using a username and password as URL query string parameters to the login URL. Users who try to do so are redirected to the login page. This update improves security.
Where: This change applies to Lightning Experience, Salesforce Classic, and all versions of the mobile app in all editions.
When: Salesforce enforces this update in Spring ’22. To get the major release upgrade date for your instance, go to Trust Status, search for your instance, and click the maintenance tab.
How: This update impacts you if your users or integrations log in or authenticate by passing un= and pw= as query string parameters to the login URL.
To review this update, from Setup, in the Quick Find box, enter Release Updates, and then select Release Updates. For Disable Users from Logging in to an Org with Login Credentials as Query String Parameters, enable the test run and note if users have login or authentication issues. If they’re redirected to the login page or see a redirect status code, change your login and authentication integrations by the Spring ’22 release.
Login Credentials Using URL Query Strings Are Disabled (Release Update) (salesforce.com)