3 ms·
Yes. This is why you never perform any actions which change something over GET. Use POST (or PUT or DELETE) for them.
by hendi_ 14y ago
Yes. This is why you never perform any actions which change something over GET. Use POST (or PUT or DELETE) for them.
- nostrademons 14y agoThis is one of the reasons why you never perform any actions which change something over GET. The main reason is so your site doesn't get deleted when the Googlebot visits. (Or more generally, so that web crawlers and other robots don't accidentally mutate the site.) Using POST is not sufficient; you also need to include an XSRF token that only the requesting page knows. It's very possible to send a POST to a third-party site with about one line of Javascript. (In the relatively early days of Reddit, I wrote a page that upvoted itself by having a JS handler in an invisible iframe resubmit the same link over again, using the visitor's login credentials. At the time, submitting the same link twice on Reddit counted as an upvote, and so merely visiting the page would upvote the link.)
- hendi_ 14y agoYou're right, I only focused on that one single reason for my post since I was in a hurry. Security issues are obviously more complex than one-line explanations. Thank you for your more elaborate reply!
- rmc 14y agoYes, that solves that. But you should use CSRF. Otherwise someone could have a <form method=POST action="http://mysite.example.com/delete>…</form> http://mysite.example.com/delete>…</form> on their site and a javascript that will submit the form upon page load.