PHP Security: send POST to same URL = bad?
php, post, redirect
Solution
It is extremely important for the purposes of web security that a POST cannot be sent via a simple URL.
I think the person who said this might have misunderstood either you or web security.
There's nothing wrong with using the same URL for different request methods (`GET`, `POST`, `PUT`, `DELETE`, `HEAD` etc). In fact, it's a very good idea.
Problem
I had a response on a question yesterday about sending POST data to the same page with the Post-Redirect-Get pattern like this: ``` if (isset($_POST['Submit'])) { // prevent resending data header("Location: " . $_SERVER['PHP_SELF']); } ``` Someone replied: sending data to same PHP page from Javascript, no AJAX or forms It is extremely important for the purposes of web security that a POST cannot be sent via a simple URL. Now I would like to know what is wrong with this? I want to avoid using a separate page with the confirmation message, because it just breaks the user experience and from a design POV it is a no-go.