Re: i19 Bodies on GET (and other) requests

2007-01-17

> "A server SHOULD read and forward a message-body on any request. If  
> the request method does not include defined semantics for an entity- 
> body, or if the request method is unrecognised, then the message-body  
> SHOULD be ignored by servers and caches when handling the request."

Looks good to me, but I don't think it really matters. The specs is
quite clear, it just takes time to grok the "ignore" aspect of GET
request message bodies when using such messages doesn't make sense. In
worst case an implementer takes the safe route and selects not to cache
the response.

But the security issues related message bodies deserves a separate
discussion in what can be done in the specs to improve the situation.


Received on Tuesday, 16 January 2007 23:46:06 UTC