Genaral practice is when you login, or do something else that requires your username and password, you send it in the body of post request. Also for added security https should be used.
In get request these parameters are sent as a part of URL. But in https both body and headers are encrypted, as i understand.
So in theory, whether you use https post or get for sending, your data are safe..., in one case attacker will have to decript your header and in other your body.
So my question is, if this is all true, how is post more secure?