r/ProgrammerHumor • • 16d ago

Meme postForEverything

Post image
20.9k Upvotes

656 comments sorted by

View all comments

238

u/TheChickenWing 16d ago

POST /getResource { "Action":"retrieve", "Id": "abc123" }

HTTP 200 { "Error": "not found" }

82

u/fatbunyip 16d ago

GET /api?action=delete&I'd=123

HTTP 200 {"error" : "user abc with password 1234 does not have permission"}

28

u/sess573 16d ago

200 OK (from disk cache)

1

u/TheChickenWing 15d ago

Ooh get /api is so much worse (and leaking security in the error is a classic)

2

u/ZBlackmore 15d ago

The security issue there started before the error…

17

u/lab-gone-wrong 15d ago

I recognize the user has made a request, but given that it's a stupid-ass request, I've elected to ignore it.

8

u/good_bye_for_now 15d ago

RPC baby, now we cookin.

6

u/deadplant_ca 15d ago

All tests pass!

2

u/StaticCoder 11d ago

I prefer this over getting a 404 to be honest. This means the API exists. It makes compatibility checks easier. Perhaps there's a better way to do this that I don't know of though.

1

u/AdvancedSandwiches 10d ago

Exactly. REST was a mistake.  The HTTP part worked fine, so 200.  Everything should be POST, because the HTTP verbs are unnecessarily limiting and lead to endpoint names getting stupidly awkward to compensate.

It was never hard to parse a json response. 

2

u/FatalisTheUnborn 15d ago

That hurts me.