4 ms·
Not OP, but https://cloud.google.com/blog/products/api-management/restful-api-design-nouns-are-good-verbs-are-bad https://cloud.google.com/blog/products/api-man
by jon_richards 2y ago
Not OP, but https://cloud.google.com/blog/products/api-management/restful-api-design-nouns-are-good-verbs-are-bad https://cloud.google.com/blog/products/api-management/restfu...
The problem is that clients generally have a bunch of verbs they need to do. You have to design your objects and permissions just right such that clients can do all their verbs without an attacker being able to PATCH "payment_status" from "Requires Payment" to "Payment Confirmed".
RPC uses verbs, so that could just be the SubmitPayment RPC's job. In REST, the correct design would be to give permission to POST a "Payment" object and base "payment_status" on whether that has been done.
- robertlagrant 2y agoThis is the most painful bit of REST for sure.