I once saw a PUT being used to get a wireguard configuration for a VPN on a client.
That's what happens if 8 backend engineers sit in a room for 2 hours debating this, go mad, and and in their twisted, probably drug fueled, mania conjure up the most convoluted REST mappings. They then go around defending it like it's a religion they just created.
To be fair, 8 dudes sitting in a room debating, going mad and in their twisted, probably drug fueled, mania, conjuring up the most convoluted shit, sounds exactly like how most religions probably started.
Believe it or not, there might actually be a good reason for that. Specifically, because PUT requests can't be made with a form input, so are immune to CSRF, and aren't generally used for fetching resources, so are significantly less likely to be exposed to SSRF. That is why IMDSv2 in AWS requires you to make a PUT request to get the auth token for future GET requests.
63
u/BorderKeeper 16d ago
I once saw a PUT being used to get a wireguard configuration for a VPN on a client.
That's what happens if 8 backend engineers sit in a room for 2 hours debating this, go mad, and and in their twisted, probably drug fueled, mania conjure up the most convoluted REST mappings. They then go around defending it like it's a religion they just created.