3 ms·
It sounds like GET with a body is just undefined behavior. Why not just standardize it? It seems to be a better way than adding a new method.
by maxloh 4mo ago
It sounds like GET with a body is just undefined behavior.
Why not just standardize it? It seems to be a better way than adding a new method.
- Vosporos 4mo agoA lot of un-updateable software out there that strip the body. Especially when the companies behind it doesn't provide support anymore.
- earthdeity 4mo agowill those support QUERY?
- WorldMaker 4mo ago1) Changes to how GET works likely require a new HTTP version to assure maximum breaking change awareness. We're already in a Postel's Law state where we have HTTP/1.1, HTTP/2, and HTTP/3 all running side-by-side for reasons that all three are very different under the hood at even the transport layers. Do we really want to add HTTP/1.2, HTTP/2.1, and HTTP/3.1 to that list? An entirely new method is easier to apply horizontally to all three versions, because the HTTP standard already allows that as an extension mechanism. (There's an IANA registry for HTTP methods and HTTP methods such as WebDAV's have always been their own standards outside of HTTP RFCs.) 2) A plain separation between GET should only accept query string parameters and QUERY should only accept body parameters potentially reduces attack surface of attackers trying to mix and match the two to find potential order of precedence attacks.