W3C home > Mailing lists > Public > whatwg@whatwg.org > October 2005

[whatwg] <a href="" ping="">

From: S. Mike Dierken <mike@dierken.com>
Date: Tue, 25 Oct 2005 20:55:59 -0700
Message-ID: <20051026035600.D673210753D@legolas.dreamhost.com>
> It's already possible to POST to arbitrary URLs just by 
> putting any old URL in the /action/ attribute of a <form> and 
> submitting it with JS or fooling the user into clicking the 
> submit button.
True. One interesting aspect of keeping the number of methods small is that
utilities can be built that operate on any number of sites and understand
how to avoid 'unsafe' operations. In the case of Flickr, if I used a
pre-fetching tool or client side spider/indexer, those images would be toast
without my knowing about it. Traversing a URI should be 'safe' - this opens
up new application possibilities.

> 
> A website like Flickr should require authentication of the 
> user before allowing photos to be deleted.
Yes, and they shouldn't use GET to modify data.
Received on Tuesday, 25 October 2005 20:55:59 UTC

This archive was generated by hypermail 2.4.0 : Wednesday, 22 January 2020 16:58:43 UTC