RFC 10008: HTTP QUERY: Safe, idempotent queries with content
Summary
RFC 10008 defines the HTTP method QUERY for complex, safe and idempotent queries with request content. New methods close gaps when established semantics do not fit cleanly. Explicit semantics are better than misused POST requests.
Ideas
- QUERY carries query parameters in the message content.
- The method does not change the state of the target.
- Responses can be cached using suitable keys.
Remarks
- RFC 10008 has the status “Proposed Standard”; current errata and successor documents should also be checked.
Recommendations
- Enable QUERY only after checking all proxy and application layers.
- Limit query complexity and input size on the server side.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.