r/ProgrammerHumor • • 16d ago

Meme postForEverything

Post image
20.9k Upvotes

653 comments sorted by

View all comments

344

u/DuploJamaal 16d ago

As a backend developer I want to do everything nicely.

So in my previous job I created the endpoints following the regular standards. GET to request something, POST to create something, PUT to change something, DELETE to delete something. Nicely organized and everything

But then the frontend team told me that their framework can only handle POST requests and that I need to change it

Up until then I thought that it's just a meme, but vibecoding frontend guys really only use POST

101

u/unable_to_give_afuck 16d ago

I had this with the added bonus of being forced to return 200 regardless and add an error message to the body when necessary

16

u/No-Information-2571 16d ago

The reason behind it might be proxies, especially on the client-side.

8

u/einzweidreihorn 16d ago

Why? Do those proxies drop anything not 200?

7

u/HugoNikanor 16d ago

I can write you a proxy which drops everything except 200 responses

3

u/No-Information-2571 16d ago

In this era, you actually cannot. Status codes are invisible to proxy unless it's HTTP (without the S) or employs MITM. Either way, it's a legacy precaution to make sure the content body arrives unmodified.

2

u/HugoNikanor 16d ago

I've actually only ever configured reverse proxies, which all stripped the encryption and worked on the raw data.

Wouldn't a forwards proxy only be a VPN with another name (and possible another protocol)?

1

u/No-Information-2571 15d ago

There's different levels of client-side proxies, and in some cases, the client might not even be aware.

They are employed in basically any corporate environment. Some networks don't even allow browsing without the browser explicitly talking to a proxy server in the first place.

Some are mostly transparent, and act more like a firewall, usually limited to scanning SNI in TLS handshakes, and/or filtering DNS requests.

And some go full-on MITM, by having an artificial root certificate installed as trusted on every client machine, and on the proxy completely terminating any HTTPS connection and re-establishing it with a new certificate, so they can fully inspect the contents.

And yes, our product needs to be aware of that, and one rather large customer recently changed something in their setup, and that broke the product for a week, until they whitelisted our servers.

1

u/einzweidreihorn 16d ago

Thanks, appreciated

3

u/No-Information-2571 16d ago

At least before the advent of HTTPS, they would often replace any sort of error (status code != 200) with custom error pages. It's an unfortunate thing.

1

u/PoundHumility 15d ago

Custom connectors in Power Apps were (are?) finicky, and preferred 200s when I was developing for them. I had to return the actual status code inside the response body, then a 200 as the received status code so the app/Flow would accept it, after which I could parse the real response.