3 ms·
It's only "dangerous" because the cache server does not care about headers. I don't see how this could affect security without broken cache server in place. If
by slykar 7y ago
It's only "dangerous" because the cache server does not care about headers. I don't see how this could affect security without broken cache server in place. If you are using the framework you should know how the dispatching works. I agree it could be disabled by default tough.
It's just an information for the routing system to dispatch a different method on a controller. You could implement a way to use a query string to pass this override too. An API framework does not have to be RESTful. It could work with POST requests only and simulate deletes with something like ?method=delete.
Edit: I saw a GitHub comment that actually says it is possible to use query string to override the method in Play 1.
https://github.com/playframework/play1/issues/1300#issuecomment-544997717 https://github.com/playframework/play1/issues/1300#issuecomm...
> We've found that although the header is disabled, its still possible to use X-HTTP-Method-Override by passing as a query string
- anderspitman 7y agoThis is why I've struggled to understand why CORS is implemented the way it is. It's so easy for developers to circumvent, but the solution is always hacky and/or semantically diluted, so you're worse off in the end.