Comment by JimDabell
8 hours ago
It sounds like you might be thinking of the Google Web Accelerator incidents with 37signals.
If that’s the case, then the delete links were behind authentication, but DHH assumed that meant it was okay to ignore the HTTP spec. and use GET for unsafe actions. Lo and behold, authenticated users with the GWA browser plugin installed deleted all their data.
Then, instead of learning from the mistake and fixing his bug, he tried to detect GWA and hide from it. Sure enough, that failed and users experienced data loss for a second time. He still continued to blame GWA, calling it “evil” and “scary”. You’d think he’d be smart enough to figure out that he needs to follow the HTTP spec., but he couldn’t admit to being wrong.
Follow the specs, people!
https://blog.moertel.com/posts/2005-10-25-google-web-acceler...
No comments yet
Contribute on Hacker News ↗