Ever hear the horror story about what happens when Google rolls through your CMS that has the "delete" button as a link?
Ever hear the horror story about what happens when Google rolls through your CMS that has the "delete" button as a link?
In particular, the convention has been established that the GET and HEAD methods SHOULD NOT have the significance of taking an action other than retrieval. These methods ought to be considered "safe". This allows user agents to represent other methods, such as POST, PUT and DELETE, in a special way, so that the user is made aware of the fact that a possibly unsafe action is being requested.
Naturally, it is not possible to ensure that the server does not generate side-effects as a result of performing a GET request; in fact, some dynamic resources consider that a feature. The important distinction here is that the user did not request the side-effects, so therefore cannot be held accountable for them.
Using get instead of post for these kind of actions is just asking for trouble.
Edit: Or so I thought. I'm wrong.
It turns out there's no standard for this, so who knows what you can do today. But practically, Google Web Accelerator doesn't prefetch links with a query string, at least currently. So Paul's voting links are A-OK with GWA. And that's the only one that you need to worry about, at least today.
http://webaccelerator.google.com/webmasterhelp.html#prefetch...
I've edited my post. Thanks for your reply.
If HTML had a method="post" option on <a>'s then it would be no problem to always use the proper HTTP verb, but we have to satisfice with what we've got.
That said, if you're already using javascript (as news.YC is), I really don't see why you wouldn't make use of xhr. In which case you could submit the request as a post.
Note: I haven't poked around enough to see if news.YC works without javascript. If they degrade gracefully, more power to them, and I can almost understand the decision to do it the way they have.