> Allow only GET requests i.e. make the internet read-only
If only developers never made use of GET to modify resources...
https://www.reddit.com/r/webdev/comments/6999x7/comment/dh4v...
If only developers never made use of GET to modify resources...
https://www.reddit.com/r/webdev/comments/6999x7/comment/dh4v...
I thought it'd be this old but memorable article: https://thedailywtf.com/articles/The_Spider_of_Doom
Of course, some websites may permit mutations through GET so it’s probably only sensible to use alongside known hosts.
GET requests are also easier to be abused in Cross Site Request Forgery (CSRF) attacks. Modern countermeasures in browsers (like SameSite cookies) will protect cross-origin POST and other state-changing methods, but will largely allow GET requests to go through while carrying session cookies.