4 ms·
I disagree with many of the posters here saying that the difference between GET and POST is irrelevant or a social construct or something like that. Intermedia
by dc-programmer 5y ago
I disagree with many of the posters here saying that the difference between GET and POST is irrelevant or a social construct or something like that.
Intermediate proxies and browsers apply different caching rules to GET vs POST responses. This can have huge performance and security implications.
Along the lines of security, browsers impose stricter security mechanisms on POST requests. Cross site POST calls require a CORS pre-flight options request, and the response of this request is scrutinized. Choosing GET vs POST can be the differences between having CSRF protections and having none.
Sometimes I feel that some of the opinions here are not very useful without the context of the environments in which they are deployed. A few weeks ago I saw someone wrote that logging is an anti-pattern because correct code doesn’t need it. That may work for a small project, just like using fat GET requests may be fine for most projects. But when you are building complex software at scale, the importance of following the normal practices becomes very evident
- andirk 5y ago> The [query] spec also makes it cachable. This, or having a body on a GET request, is the best option due to caching implications, of which said implications are often opinionated (not according to a spec) along the entire path of request/response.
- luhn 5y ago> Cross site POST calls require a CORS pre-flight options request, and the response of this request is scrutinized. Not in all cases. Certain POST requests count as "simple" requests and no preflight check is performed. For example, a POST with application/x-www-form-urlencoded data and no extra headers doesn't need a preflight, because you could make an equivalent request with an HTML form. https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#simple_requests https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#simpl...
- deleted 5y ago[deleted]
- capableweb 5y agoAnd continuing on that note, non-simple cross-origin GET requests initiated via JS also requires a pre-flight OPTIONS request (actually any non-simple HTTP request would require this). See https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#simple_requests https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#simpl...
- aprinsen 5y ago> logging is an anti-pattern Tell me you're still seeking product market fit without telling me you're still seeking product market fit
- syspec 5y agoTell you this is not Reddit, without telling you this is not Reddit
- hiptobecubic 5y agoNo logging might "work" for a small project, but only in the way that not wearing clothes might "work" if you're only running outside to grab your mail then running back inside.
- brazzledazzle 5y agoI choose to believe the comment you saw about logging was a satirical play on the idea that good code requires no comments.