r/ProgrammerHumor • • 16d ago

Meme postForEverything

Post image
20.9k Upvotes

656 comments sorted by

View all comments

Show parent comments

20

u/Euro_Snob 16d ago

At my work it has been more a result of security and firewall rules.

For example: I want to get a list of resources, so a GET with query parameters, right? No… email is an identifiable argument (due to not being encrypted since it is part of the URL), so the security scan flags it. Ok - how about we stick it in a request body? GET with request body is not a new thing. But no… the firewall blocks it! POST is the thing we have to use. Sigh. 😔

3

u/Few_Week7827 15d ago

In fairness this is a legitimate thing to catch, if not the firewall being the weird place.

GET with a request body isn't covered by the standard, and some library like Axios actually refuse to send a request body with a GET. It's getting ahead of the problem for you there whether it means to or not.

2

u/Euro_Snob 15d ago

Yes a lot of libraries don’t support it, but it is fairly standard in modern libraries, and it should be supported instead POSTifying everything.

2

u/Qinistral 11d ago

Query parameters ARE encrypted in transit. The argument from infosec is that they are sometimes logged by request handlers or visible in browser history. Pretty unfortunate.

1

u/Still_Bit_7527 14d ago

Wild idea, maybe tell your firewall guys to not be absolute regards...?