2 ms·
Yeah I really don't understand the anti-GET-body argument. "Using GET with a body isn't in the spec, WAFs and webservers that haven't been updated might reject
by akersten 4mo ago
Yeah I really don't understand the anti-GET-body argument.
"Using GET with a body isn't in the spec, WAFs and webservers that haven't been updated might reject it!"
Ok, QUERY wasn't in the spec when those were written either. What do you expect those appliances to do with a totally unknown verb?
It's a welcome addition but the new method is pure marketing. There's no reason the update couldn't have been to expand GET instead of add support for QUERY.
- WorldMaker 4mo ago> What do you expect those appliances to do with a totally unknown verb? 405 Method Not Allowed We have existing standards for unsupported methods.
- locknitpicker 3mo ago> Using GET with a body isn't in the spec, It's exactly the opposite. The HTTP spec does cover GET with bodies. However, what you fail to account is that the spec specifies they are invalid and a GET with body is meaningless, and represents a potential attack.