Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, there is also something as "state". You don't want "method=delete" to work as POST either, unless the client is authorized. Same with GET. I don't see why POST would be better than GET really.


Theoretical reason: because that's what the HTTP spec says.

Practical reason: because browsers have prefetching systems that might GET resources without asking the user, which might be authorized anyway.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: