<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: REST Mistake #1: Confirming GETs</title>
	<atom:link href="http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/feed/" rel="self" type="application/rss+xml" />
	<link>http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/</link>
	<description>Longer than a blog; shorter than a book</description>
	<pubDate>Fri, 05 Dec 2008 10:46:36 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: spyware removal software</title>
		<link>http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-95399</link>
		<dc:creator>spyware removal software</dc:creator>
		<pubDate>Thu, 31 May 2007 20:45:39 +0000</pubDate>
		<guid isPermaLink="false">http://minicafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-95399</guid>
		<description>&lt;strong&gt;spyware removal software&lt;/strong&gt;

Features of spyware removal software.</description>
		<content:encoded><![CDATA[<p><strong>spyware removal software</strong></p>
<p>Features of spyware removal software.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bÃ¶rsenspiel</title>
		<link>http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-87013</link>
		<dc:creator>bÃ¶rsenspiel</dc:creator>
		<pubDate>Mon, 07 May 2007 22:19:35 +0000</pubDate>
		<guid isPermaLink="false">http://minicafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-87013</guid>
		<description>technically it is within a clientâ€™s right to pre-fetch any URLs they desire. But in an email client that seems irresponsible, when some of those URLs might be:Click here to confirm for my spam list that your email address is valid!</description>
		<content:encoded><![CDATA[<p>technically it is within a clientâ€™s right to pre-fetch any URLs they desire. But in an email client that seems irresponsible, when some of those URLs might be:Click here to confirm for my spam list that your email address is valid!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: toscana</title>
		<link>http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-78119</link>
		<dc:creator>toscana</dc:creator>
		<pubDate>Mon, 16 Apr 2007 04:46:15 +0000</pubDate>
		<guid isPermaLink="false">http://minicafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-78119</guid>
		<description>E grande io ha trovato il vostro luogo! Le info importanti ottenute! ))</description>
		<content:encoded><![CDATA[<p>E grande io ha trovato il vostro luogo! Le info importanti ottenute! ))</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Test</title>
		<link>http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-70108</link>
		<dc:creator>Test</dc:creator>
		<pubDate>Fri, 30 Mar 2007 05:29:15 +0000</pubDate>
		<guid isPermaLink="false">http://minicafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-70108</guid>
		<description>Hi all! 
 
 
G'night</description>
		<content:encoded><![CDATA[<p>Hi all! </p>
<p>G&#8217;night</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BillSaysThis</title>
		<link>http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-310</link>
		<dc:creator>BillSaysThis</dc:creator>
		<pubDate>Sat, 15 Apr 2006 18:33:38 +0000</pubDate>
		<guid isPermaLink="false">http://minicafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-310</guid>
		<description>Both the GET and POST versions seem to require two clicks to me. One in the email to load the confirm page and one to dismiss the page; after all, even assuming a multi-tab capable browser not many of us are likely to leave the tab open. Further, why would you have separate Verify and Go to button/links in the POST version rather than Confirm (and Not Me) buttons which load the next page/close the tab after submission?</description>
		<content:encoded><![CDATA[<p>Both the GET and POST versions seem to require two clicks to me. One in the email to load the confirm page and one to dismiss the page; after all, even assuming a multi-tab capable browser not many of us are likely to leave the tab open. Further, why would you have separate Verify and Go to button/links in the POST version rather than Confirm (and Not Me) buttons which load the next page/close the tab after submission?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: marten.gustafson &#187; links for 2006-03-21</title>
		<link>http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-251</link>
		<dc:creator>marten.gustafson &#187; links for 2006-03-21</dc:creator>
		<pubDate>Tue, 21 Mar 2006 22:20:54 +0000</pubDate>
		<guid isPermaLink="false">http://minicafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-251</guid>
		<description>[...] REST Mistake #1: Confirming GETs (tags: rest) [...]</description>
		<content:encoded><![CDATA[<p>[...] REST Mistake #1: Confirming GETs (tags: rest) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bloglips - douglips blog</title>
		<link>http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-250</link>
		<dc:creator>bloglips - douglips blog</dc:creator>
		<pubDate>Tue, 21 Mar 2006 21:06:15 +0000</pubDate>
		<guid isPermaLink="false">http://minicafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-250</guid>
		<description>&lt;strong&gt;Confirming GETs Considered Harmful?&lt;/strong&gt;

Now, technically it is within a client's right to pre-fetch any URLs they desire. But in an email client that seems irresponsible, when some of those URLs might be:Click here to confirm for my spam list that your email address is valid! (Note, this is...</description>
		<content:encoded><![CDATA[<p><strong>Confirming GETs Considered Harmful?</strong></p>
<p>Now, technically it is within a client&#8217;s right to pre-fetch any URLs they desire. But in an email client that seems irresponsible, when some of those URLs might be:Click here to confirm for my spam list that your email address is valid! (Note, this is&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elliotte Rusty Harold</title>
		<link>http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-249</link>
		<dc:creator>Elliotte Rusty Harold</dc:creator>
		<pubDate>Tue, 21 Mar 2006 15:14:09 +0000</pubDate>
		<guid isPermaLink="false">http://minicafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-249</guid>
		<description>That has several problems. First, from a theoretical standpoint I'm not sure that running the confirming script automatically on the client in response to a GET is any different than running a script automatically on the server.

Second, from a user interface perspective, the user expects to be able to click on a basic link without confirming or committing to anything.

Third, practically, I'm not at all sure that Google (and other robots) won't run JavaScript in the future. They're already making efforts to process the HTML more as a real browser like Firefox would  in order to identify the more and less important content on the page.</description>
		<content:encoded><![CDATA[<p>That has several problems. First, from a theoretical standpoint I&#8217;m not sure that running the confirming script automatically on the client in response to a GET is any different than running a script automatically on the server.</p>
<p>Second, from a user interface perspective, the user expects to be able to click on a basic link without confirming or committing to anything.</p>
<p>Third, practically, I&#8217;m not at all sure that Google (and other robots) won&#8217;t run JavaScript in the future. They&#8217;re already making efforts to process the HTML more as a real browser like Firefox would  in order to identify the more and less important content on the page.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Avery Regier</title>
		<link>http://cafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-248</link>
		<dc:creator>Avery Regier</dc:creator>
		<pubDate>Mon, 20 Mar 2006 14:34:47 +0000</pubDate>
		<guid isPermaLink="false">http://minicafe.elharo.com/web/rest-mistake-1-confirming-gets/#comment-248</guid>
		<description>Use javascript on the page you get by the GET call from the mail message to automatically submit the form which then confirms the message.  Unless JavaScript is turned off, this will be one click.  If JavaScript is turned off or the browser somehow prevents it, it is two.  Google's spidering won't run the JavaScript, so it is safe there.</description>
		<content:encoded><![CDATA[<p>Use javascript on the page you get by the GET call from the mail message to automatically submit the form which then confirms the message.  Unless JavaScript is turned off, this will be one click.  If JavaScript is turned off or the browser somehow prevents it, it is two.  Google&#8217;s spidering won&#8217;t run the JavaScript, so it is safe there.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
