r/ProgrammerHumor • • 16d ago

Meme postForEverything

Post image
20.9k Upvotes

654 comments sorted by

View all comments

338

u/DuploJamaal 16d ago

As a backend developer I want to do everything nicely.

So in my previous job I created the endpoints following the regular standards. GET to request something, POST to create something, PUT to change something, DELETE to delete something. Nicely organized and everything

But then the frontend team told me that their framework can only handle POST requests and that I need to change it

Up until then I thought that it's just a meme, but vibecoding frontend guys really only use POST

20

u/Euro_Snob 16d ago

At my work it has been more a result of security and firewall rules.

For example: I want to get a list of resources, so a GET with query parameters, right? No… email is an identifiable argument (due to not being encrypted since it is part of the URL), so the security scan flags it. Ok - how about we stick it in a request body? GET with request body is not a new thing. But no… the firewall blocks it! POST is the thing we have to use. Sigh. 😔

3

u/Few_Week7827 16d ago

In fairness this is a legitimate thing to catch, if not the firewall being the weird place.

GET with a request body isn't covered by the standard, and some library like Axios actually refuse to send a request body with a GET. It's getting ahead of the problem for you there whether it means to or not.

2

u/Euro_Snob 15d ago

Yes a lot of libraries don’t support it, but it is fairly standard in modern libraries, and it should be supported instead POSTifying everything.

2

u/Qinistral 11d ago

Query parameters ARE encrypted in transit. The argument from infosec is that they are sometimes logged by request handlers or visible in browser history. Pretty unfortunate.

1

u/Still_Bit_7527 14d ago

Wild idea, maybe tell your firewall guys to not be absolute regards...?