skip to content

questions

page 2 of 2

What does the HTTP specification say about sending a request body with a GET, and what should you do instead when query criteria are too large for a URL?

level: seniorimportance: nice to knowfreq 35%

basics

~20 s

RFC 9110 says content on a GET has no defined semantics, so servers may ignore or reject it and intermediaries may strip it — GET bodies are unreliable. For large criteria use POST with a body, or a two-step POST-then-GET so results stay cacheable.

open as a page

The HTTP TRACE method makes a server echo the received request back to the client. What is it meant to be used for, and why do most production servers and proxies disable it?

level: seniorimportance: nice to knowfreq 25%

basics

~20 s

TRACE is a loop-back diagnostic: the final server echoes the request it received back as the response body, revealing how proxies rewrote it. It is disabled because the echo reflects cookies, Authorization headers, and internal proxy headers back to the caller — information disclosure, historically exploited as Cross-Site Tracing.

open as a page

An HTTP/1.1 response starts with a line like 'HTTP/1.1 404 Not Found'. What happened to that trailing reason phrase in HTTP/2 and HTTP/3, and what breaks in software that depends on it?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

HTTP/2 and HTTP/3 dropped reason phrases entirely: a response carries only the three-digit :status pseudo-header. Anything that read, logged, asserted on, or smuggled information through the phrase gets nothing — clients synthesize a phrase from a lookup table or leave it empty.

open as a page

showing 31–33 of 33