Hacker News new | ask | show | jobs
HTTP Safety Doesn't Happen by Accident (robots.thoughtbot.com)
2 points by dpmehta02 4018 days ago
1 comments

It's too bad we don't have <a href=... method="post">.

The distinction between safe and unsafe is not only useful for things like prefetching or caching but also for csrf. State mutation (whether intentional or accidental) on get requests can totally undermine your site's web security.