3 ms·
This is an amusing what-if discussion but none of these semi-serious suggestions would be workable. The beauty of HTTP is that servers are simple (HTTP2/3 comp
by AndrewStephens 4y ago
This is an amusing what-if discussion but none of these semi-serious suggestions would be workable.
The beauty of HTTP is that servers are simple (HTTP2/3 complicates things). HTTP clients have to implement all sorts of painful encodings and caching but a server (begin in charge of the conversation) can ignore all of that and be incredibly dumb.
Of these suggestions, BUY might be the most useful but it is really just a PUSH with extra data that needs to be sent anyway.
REMEMBER (server side cookies) sounds like a good idea (after all, HTTPS, etc maintain state per connection) but quickly becomes a DoS attack once a client decides to get the server to REMEMBER 10 million sessions.
HELP is not useful, nobody uses HTTP interactively and clients don't really bother negotiating any more.
God knows how UNDO is supposed to be implemented.
- xani_ 4y ago> The beauty of HTTP is that servers are simple (HTTP2/3 complicates things). HTTP clients have to implement all sorts of painful encodings and caching but a server (begin in charge of the conversation) can ignore all of that and be incredibly dumb. That kinda stopped being true with all of the security theatre headers browsers want app to provide to be "secure". First we had CORS, that failed and had to be expanded every year or two, now we have the whole capabilities things, which means web server can't just serve web and even simple server serving static JS with maybe some JSON API needs to have logic for generating right headers for right page.
- blowski 4y agoI’m not sure CORS has failed. It’s forced a lot of teams to put internal apis on the same host, which is a security win.
- capableweb 4y agoYeah, either putting the content + backend behind the same Origin, or just add `Access-Control-Allow-Origin: *` as a header to all requests (and the other ones), which one you think is most popular for people with no time to build things properly? ;)
- P5fRxh5kUvp2th 4y agoI agree with you, but there are those of us who push for putting everything behind the same origin and we succeed in that because most people are aware of how painful CORS is. So, in some ways, CORS being so painful is actually helping (tongue-in-cheek, but it has some truth to it).
- blowski 4y agoWith CORS we can choose from: 1. Apply more specific security appropriate for your use case 2. Put it on the same host 3. Origin *. Teams that do this probably have bigger security problems anyway. Without CORS, we'd all be stuck choosing between 2 and 3.
- AndrewStephens 4y agoThe server doesn't really need to serve those headers - what does it care if the client won't load the scripts, or whatever? HTTP is more than serving HTML.