# List of all users http://localhost:1337/user
# Find the user with id 1 http://localhost:1337/user/1
# Create a new user http://localhost:1337/user/create?name=Fisslewick (or send an HTTP POST to http://localhost:1337/user)
# Update the name of the user with id 1 http://localhost:1337/user/update/1?name=Gordo (or send an HTTP PUT to http://localhost:1337/user/1)
# Destroy the user with id 1 http://localhost:1337/user/destroy/1 (or send an HTTP DELETE to http://localhost:1337/user/1)
nice work btw, the end to end of it is attractive if somewhat magical.
Also, if someone does manage to find an XSS vulnerability, using a CSRF token won't be any good - the attacker can simply read the token from your website and use it.
Then if your authentication is cookie based and you allow to delete resource via GET then all the attacker have to do is to insert <script> or <img> tag on any other domain with the proper src attribute to delete your content silently.
These endpoints are a VERY bad idea and are absolutly not REST. RESTful do not mean CRUD.
POST requests can be easily sent cross-domain. NO ONE SHOULD EVER think that just because he's not using GET requests he's safe from CSRF attacks.
[1] See http://jsfiddle.net/8xnB3/5/ for example (which sent this comment).
EDIT: Just to clarify - I'm not saying that exposing those endspoints via GET is a good idea, I think its horrible. But people should be aware that avoiding GET does not protect against CSRF, and you still have to use CSRF tokens.
Reference: https://www.owasp.org/index.php/Top_10_2013-A8-Cross-Site_Re...
"GET request are not supposed to imply any modification on the serveur."
Remember C++ constness?
I can certainly see the desire for that as a browser feature; using GET for actions that are neither safe (no impact other than retrieval) nor idempotent is probably not a good way to workaround the lack of such a browser feature, since per the HTTP/1.1 spec, GET should be safe and is defined as idempotent. (See Secs. 9.1.1 and 9.1.2 of RFC 2616.)
But seriously, I'm new to Node. If I see examples of bad practice on the home page, I've no way of knowing if the framework is going to be teaching me more bad practices in the areas I'm not familiar with yet.