Re: XHR security risks

On 2006/06/08, at 6:41 AM, Charles McCathieNevile wrote:

> There is a convention that you don't use GET for things with side  
> effects, but there is nothing that enforces that convention.

Caching proxies
Search engines and other automated processes
Google Web accelerator

I think it's very effectively enforced, by the Web itself. Remember,  
2616 doesn't say that there can't be side effects, just that the  
server has to be able to live with them without blaming the user...

--
Mark Nottingham
mnot@yahoo-inc.com

Received on Thursday, 8 June 2006 16:27:33 UTC