Featured post
Why do we do a POST to confirm deletion in asp.net MVC? -
the following note professional asp.net mvc 2 scott hanselman ++
you might ask — why did go through effort of creating <form> within our delete confi rmation screen? why not use standard hyperlink link action method actual delete operation? reason because want careful guard against web-crawlers , search engines discovering our urls , inadvertently causing data deleted when follow links. http-get-based urls considered safe them access/crawl, , supposed not follow http-post ones. rule make sure put destructive or data-modifying operations behind http-post requests.
if web-crawlers , search engine have no access page containing deletion button, safe use standard hyperlink link action method doing actual delete operation?
a rule of thumb shouldn't change data. if want change data use post.
that why scottha etc used form submit delete. if doesn't work app can use if needed.
alternatively use javascript submit form whe user clicks link.
- Get link
- X
- Other Apps
Comments
Post a Comment