4 ms·
Well, there is also something as "state". You don't want "method=delete" to work as POST either, unless the client is authorized. Same with GET. I don't see why
by pors 15y ago
Well, there is also something as "state". You don't want "method=delete" to work as POST either, unless the client is authorized. Same with GET. I don't see why POST would be better than GET really.
- icebraining 15y agoTheoretical reason: because that's what the HTTP spec says. Practical reason: because browsers have prefetching systems that might GET resources without asking the user, which might be authorized anyway.