Re: User confirmation and 307 redirects

On Thu, Aug 19, 2010 at 5:37 PM, Roy T. Fielding <> wrote:
> There is no compelling need for auto-redirect for an unsafe method.
> If you can't figure out a safe way that your "user" (an entity which
> varies substantially based on the type of HTTP client being used)
> can approve of the redirect

The term "user" has a very vague definition. That's OK. But that
variance makes RFC 2119 requirements that hinge on consulting the user
very close to meaningless.


Robert Sayre

"I would have written a shorter letter, but I did not have the time."

Received on Thursday, 19 August 2010 22:23:54 UTC