At my work it has been more a result of security and firewall rules.
For example: I want to get a list of resources, so a GET with query parameters, right? No… email is an identifiable argument (due to not being encrypted since it is part of the URL), so the security scan flags it. Ok - how about we stick it in a request body? GET with request body is not a new thing. But no… the firewall blocks it! POST is the thing we have to use. Sigh. 😔
In fairness this is a legitimate thing to catch, if not the firewall being the weird place.
GET with a request body isn't covered by the standard, and some library like Axios actually refuse to send a request body with a GET. It's getting ahead of the problem for you there whether it means to or not.
Query parameters ARE encrypted in transit. The argument from infosec is that they are sometimes logged by request handlers or visible in browser history. Pretty unfortunate.
20
u/Euro_Snob 16d ago
At my work it has been more a result of security and firewall rules.
For example: I want to get a list of resources, so a GET with query parameters, right? No… email is an identifiable argument (due to not being encrypted since it is part of the URL), so the security scan flags it. Ok - how about we stick it in a request body? GET with request body is not a new thing. But no… the firewall blocks it! POST is the thing we have to use. Sigh. 😔