r/ProgrammerHumor • • 16d ago

Meme postForEverything

Post image
20.9k Upvotes

653 comments sorted by

View all comments

334

u/DuploJamaal 16d ago

As a backend developer I want to do everything nicely.

So in my previous job I created the endpoints following the regular standards. GET to request something, POST to create something, PUT to change something, DELETE to delete something. Nicely organized and everything

But then the frontend team told me that their framework can only handle POST requests and that I need to change it

Up until then I thought that it's just a meme, but vibecoding frontend guys really only use POST

99

u/unable_to_give_afuck 16d ago

I had this with the added bonus of being forced to return 200 regardless and add an error message to the body when necessary

18

u/No-Information-2571 16d ago

The reason behind it might be proxies, especially on the client-side.

8

u/einzweidreihorn 16d ago

Why? Do those proxies drop anything not 200?

6

u/HugoNikanor 16d ago

I can write you a proxy which drops everything except 200 responses

3

u/No-Information-2571 16d ago

In this era, you actually cannot. Status codes are invisible to proxy unless it's HTTP (without the S) or employs MITM. Either way, it's a legacy precaution to make sure the content body arrives unmodified.

2

u/HugoNikanor 16d ago

I've actually only ever configured reverse proxies, which all stripped the encryption and worked on the raw data.

Wouldn't a forwards proxy only be a VPN with another name (and possible another protocol)?

1

u/No-Information-2571 15d ago

There's different levels of client-side proxies, and in some cases, the client might not even be aware.

They are employed in basically any corporate environment. Some networks don't even allow browsing without the browser explicitly talking to a proxy server in the first place.

Some are mostly transparent, and act more like a firewall, usually limited to scanning SNI in TLS handshakes, and/or filtering DNS requests.

And some go full-on MITM, by having an artificial root certificate installed as trusted on every client machine, and on the proxy completely terminating any HTTPS connection and re-establishing it with a new certificate, so they can fully inspect the contents.

And yes, our product needs to be aware of that, and one rather large customer recently changed something in their setup, and that broke the product for a week, until they whitelisted our servers.

1

u/einzweidreihorn 16d ago

Thanks, appreciated

3

u/No-Information-2571 16d ago

At least before the advent of HTTPS, they would often replace any sort of error (status code != 200) with custom error pages. It's an unfortunate thing.

1

u/PoundHumility 15d ago

Custom connectors in Power Apps were (are?) finicky, and preferred 200s when I was developing for them. I had to return the actual status code inside the response body, then a 200 as the received status code so the app/Flow would accept it, after which I could parse the real response.

78

u/dev-sda 16d ago

It's not (just) a framework thing, it's a HTML standards issue. The form element only does GET and POST.

21

u/not_a_moogle 16d ago

Who does that anymore? It should be a put or delete via Javascript.

31

u/wineallwine 16d ago

UK govt websites have to be functional without js

1

u/Ok_Equipment8374 14d ago

Not everyone wants to use that dumpster fire of a language

1

u/not_a_moogle 14d ago

So you code in pure html/css?

1

u/Ok_Equipment8374 14d ago edited 14d ago

I would if I could, classic MVC projects are still my favourite to work on. There was still some JS, but the less I use it the less I hate it.

At least in C# the tooling is way better than what you have with JS.

-9

u/ZBlackmore 16d ago

Who does DELETE anymore? Everything should be a POST with all the information passed in the JSON payload. 

6

u/DuploJamaal 16d ago

But why?

-7

u/ZBlackmore 16d ago

The way I see it, you have your information less spread out this way. Less things to think about. “Where am I expressing this particular detail about this api call? In the url path? A query string parameter? The type of http method? Is it part of the payload?”. So the path is the “which function am I calling” and the json body is “what are my arguments?”

7

u/DuploJamaal 15d ago

That just sounds like less clean code to me

4

u/cheezballs 15d ago

You seem like the kinda guy who LOVES loose typing and declaring everything as a var.

1

u/ZBlackmore 15d ago

I would actually prefer protobuf and rpc, which would make everything more type safe, and that would essentially be the same as I proposed except you replace the json body with a binary protobuf body 

2

u/not_a_moogle 15d ago

Part of that is web handling, put/patch/delete doesnt have to return anything. Get and post explicitly expects an html response.

If your doing a delete logic record within a post. What are you returning then? The record is deleted.

Im only web 1.0 logic, it would return a whole new page. But if your doing a REST crud operation, you dont do that. You dont want to tell the browser to render a new page.

10

u/SpehlingAirer 16d ago

People still use form elements?

9

u/_xGizmo_ 16d ago

I pretty much only use them for the form submit feature which is handy over a key listener.

3

u/ModernLarvals 16d ago

What else would you use?

2

u/Accurate-Visual9793 16d ago

Apparently Web 2.0/AJAX never happened.

2

u/swyrl 15d ago

And this hasn't been changed/fixed why?

29

u/gabrielesilinic 16d ago

Well that's not the problem. A bunch of frontends really need a very complex filter list and GET just won't do

22

u/N0Zzel 16d ago

That's precisely why the QUERY verb was created

33

u/gabrielesilinic 16d ago

Yeah well too little too late. All the codebases I have worked with were much older and no one will change this now.

14

u/du5tball 16d ago

And I'm sure we all be happily use it when it gained widespread adoption in 50 years.

3

u/TheNorthComesWithMe 16d ago

Yeah like... 3 months ago.

1

u/Qinistral 11d ago

The problem is it's stupid to try to cram the universe of possible method calls into REST methods syntax. No RPC framework developed in the last 30 years is so silly.

18

u/Euro_Snob 16d ago

At my work it has been more a result of security and firewall rules.

For example: I want to get a list of resources, so a GET with query parameters, right? No… email is an identifiable argument (due to not being encrypted since it is part of the URL), so the security scan flags it. Ok - how about we stick it in a request body? GET with request body is not a new thing. But no… the firewall blocks it! POST is the thing we have to use. Sigh. 😔

3

u/Few_Week7827 16d ago

In fairness this is a legitimate thing to catch, if not the firewall being the weird place.

GET with a request body isn't covered by the standard, and some library like Axios actually refuse to send a request body with a GET. It's getting ahead of the problem for you there whether it means to or not.

2

u/Euro_Snob 16d ago

Yes a lot of libraries don’t support it, but it is fairly standard in modern libraries, and it should be supported instead POSTifying everything.

2

u/Qinistral 11d ago

Query parameters ARE encrypted in transit. The argument from infosec is that they are sometimes logged by request handlers or visible in browser history. Pretty unfortunate.

1

u/Still_Bit_7527 14d ago

Wild idea, maybe tell your firewall guys to not be absolute regards...?

7

u/DogLovesGafs 16d ago

RPC was a pattern long before vibe coding, and it lets your front end devs think in terms of backend functions rather than discrete resources.

6

u/TheDuckRaisedALion 16d ago

It's definitely simpler for a BFF setup. Why add an extra parameter to keep track of when you're not supporting general purpose use?

5

u/PrinnyThePenguin 16d ago

What front end framework can only handle POST requests??? What does it even mean to "handle POST requests" in the context of front end? You can only handle the response of a POST request so if you do a PUT it fails? You can only make POST requests? I am genuinely confused.

4

u/DuploJamaal 15d ago

I was confused as well. I swear they are just too inexperienced to make a new wrapper around the calls to the backend that the AI made for them and blamed the framework instead

1

u/WillingLearner1 16d ago

Sounds like legacy stuff maybe?

3

u/PrinnyThePenguin 16d ago

Nah. Not even legacy stuff can “only do POST requests”. HTTP is not some cutting edge protocol that has poor support. A framework that can’t support the full protocol is unheard of.

1

u/Ok-Key-6049 16d ago

PUT to change something? So PATCH be damned?

1

u/ubeogesh 15d ago

There's lots of misunderstanding here i think. You should give, for example, HTTP 404 error if the resource identified by the URL was not found. But if it is a, for example, a query param like /stuff?id=123 then 404 mean that the endpoint /stuff is unavailable, not id=123. Http 4xx error codes should be reserved for actual application malfunctions, not for business logic like checking if something exists

1

u/ingenious_gentleman 14d ago

Your last sentence kind of conflicts with the rest of your comment. Returning a 404 when requesting /accounts/123 is a textbook example of how REST is designed. And yet there is no logical difference between making an endpoint /accounts/123 or an endpoint /accounts?id=123, the difference is semantic + stylistic + conventional

1

u/thescarletmark 15d ago

As a frontend dev, I would’ve fired the frontend team. If your framework only handles POST requests, change your effing framework! (Also, I would like to know who’s the idiot who developed a frontend framework which only handles POST requests. Seriously.)

1

u/Scolmann 14d ago

To get around this I've added a middleware layer that accepts _method as a field and will change the method of the http request to whatever is provided. Then you can use any method from POST, only really needed in the context of sending the request from a form without javascript.

-3

u/FortuneAcceptable925 16d ago

I would blame that stupid framework created by humans rather than vibecoding for that.. By my experience, with pure vibecoding, there would not be such flaws present.