| ▲ | topham 3 hours ago | |
QUERY won't be supported by them either. So, change is required. Just change GET to allow for body and move on. Most of the systems that are blocking GET/body could be easily tweaked to allow it. Today. As is. QUERY will likely need firmware updates, core engine updates, etc. Meanwhile, tweaking GET is a rule change. | ||
| ▲ | akersten 6 minutes ago | parent [-] | |
Yeah I really don't understand the anti-GET-body argument. "Using GET with a body isn't in the spec, WAFs and webservers that haven't been updated might reject it!" Ok, QUERY wasn't in the spec when those were written either. What do you expect those appliances to do with a totally unknown verb? It's a welcome addition but the new method is pure marketing. There's no reason the update couldn't have been to expand GET instead of add support for QUERY. | ||