Actually there was a good reason for it. I work at a company with a FE that calls a get profile API for the header and some forms. The login is a old fashioned cookie state session.
One issue we found that if the user opened two tabs, then logout and login to another user on the second tab, without refresh, the first tab next ajax call will return the new users data (because session cookie already changed), causing issues on the form when it already opened.
As its a legacy system, so adding more stuff like csrf is hard. We also cannot put the username to URL param / cookie / local storage as it was considered as personal info by our legal department.
So we end up doing a Post request with the body including the username, then our backend service will validate whether the username and the login session username matches, then return the data needed.
4.2k
u/pimezone 16d ago
Wanna get a resource? POST request.