The Redirect app reveals the password in plain text to the proxied app

I think the threat model is where I want to put an untrusted app (running in a docker container, for example) behind an SSO and the SSO is revealed to the app