From: mathew
Date: 2008-10-20T00:55:24+09:00
Subject: [ruby-core:19393] Re: Net::HTTP.post_form bug : can't post form to correct uri which contains QueryString(QueryString part are lost) and revise
2008/10/17 Matt Todd :
> From my experience, it's simply easier to process requests that way,
> not ignoring query params for POST requests, etc. Not to say they
> didn't do it deliberately, but I'm not sure it's in the spec that they
> have to (or don't).
The specification for URIs is RFC3986, and the specification for HTTP
is RFC 2616.
The previous version of the URI specification, RFC 2396, is clearer
about this issue. It says:
"The query component is a string of information to be interpreted by
the resource."
This means that the query part of the URI is never part of the address
of a resource; it is always a string of information which is to be
passed to a resource.
If we then move on to the HTTP spec, it says (section 9.5):
"The POST method is used to request that the origin server accept the
entity enclosed in the request as a new subordinate of the resource
identified by the Request-URI in the Request-Line."
So POST methods can only be applied to a resource. And a resource
cannot require a query to address it. Therefore Ruby's behavior is
correct. If you know of a product that requires a query parameter as
part of the address of a resource, you should file a bug report
against that product. (And if the product is IBM Lotus Domino, I can
tell you in advance that you do not, in fact, need query parameters to
address resources, even though that's the syntax generally generated
by Domino applications for their GET URIs.)
Informally, it makes no sense to allow query parameters as well as
encoded body data in an HTTP POST. You are basically sending two
conflicting sets of parameters.
mathew
--
http://www.pobox.com/~meta/