URIs are easier to deal with but not _that_ much easier if you're programmatically sending the requests as one might expect to do with an API
* Other data formats also exist
URIs are easier to deal with but not _that_ much easier if you're programmatically sending the requests as one might expect to do with an API
* Other data formats also exist
It's pretty common advice to recommend any APIs that require user authentication to be sent via POST. In fact it's one of the first things pen testers will check for and you'd also fail PCI DSS vulnerability scans for exposing APIs via GET as well.
Disclaimer: I've works on multiple projects that have been pen tested, been audited by the UK Gambling Commission and/or had to adhere to PCI Data Security Standards.
Why do you want to 'disclaim' that? Assuming it's true, you might have meant 'disclosure', but I think what you really mean is much closer to 'source' - i.e. 'why I know this'.