Hacker News new | ask | show | jobs
by wilg 1075 days ago
It does because the requirement is only for destructive actions
1 comments

The requirement is for POSTs in general, not just deletes. Anything that does actions outside of the system instead of just getting data
The wording is ambiguous, but probably should apply. Also the rule should not be based on HTTP verbs at all since that's the wild west.