Seriously? Look at the HTTP protocol and tell me you really believe that.
Their way:
DELETE /something HTTP/1.1
My way:
GET /delete/something HTTP/1.1
Do you really think one is more secure than the other?
Their way:
DELETE /something HTTP/1.1
My way:
GET /delete/something HTTP/1.1
Do you really think one is more secure than the other?
If I was phishing to get you to click on a link to delete a resource, then I would need to know that token, and if I knew that token, then I could just delete it myself. Note that the HAPI spec discourages the use of cookies (which I agree could allow a phishing attack if you were using cookies as a security mechanism).