Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

safe-method-w-body: mention security aspects of moving query component into body #1895

Open
reschke opened this issue Jan 20, 2022 · 2 comments

Comments

@reschke
Copy link
Contributor

reschke commented Jan 20, 2022

David Slik (https://lists.w3.org/Archives/Public/ietf-http-wg/2022JanMar/0081.html):

Moving query parameters from the request URI to the request body improves overall security, given that the request URI is often cached, stored, logged and otherwise potentially disclosed by intermediary systems. As a result, if PII or other sensitive information is included in the query section of an URI, it is at a higher risk when compared to when it is included in the request body.

A description of this advantage may be worth including.

@candoumbe
Copy link

The security advantage mentioned here could also be viewed as a debug/development drawback because the server most of the time logs urls to have some insights on what was requested by the 'client'.

@asbjornu
Copy link

asbjornu commented Nov 3, 2022

Related to the discussion in #1909. I agree with @candoumbe that if any advice is given, some pros and cons of both alternatives should probably be enumerated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

No branches or pull requests

3 participants