Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, there is also something as "state". You don't want "method=delete" to work as POST either, unless the client is authorized. Same with GET. I don't see why POST would be better than GET really.


Theoretical reason: because that's what the HTTP spec says.

Practical reason: because browsers have prefetching systems that might GET resources without asking the user, which might be authorized anyway.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: