|
|
|
|
|
by amenod
2686 days ago
|
|
Which still doesn't change GP's point though: > In particular, the convention has been established that the GET and HEAD methods SHOULD NOT have the significance of taking an action other than retrieval. These methods ought to be considered "safe". (there's an exception listed too, but doesn't apply to logout) EDIT: I know of someone who made a backup of their wiki by simply doing a crawl - only to find out later that "delete this page" was implemented as links, and that the confirmation dialog only triggered if you had JS enabled. It was fun restoring the system. |
|