Skip to content

More endpoints that use DELETE with body #5193

@jakub-bochenski

Description

@jakub-bochenski

Current Behavior

v1/tag
v1/tag/$tag_name/policy
v1/tag/$tag_name/project

Expected Behavior

As clarified by RFC 9110 using method body in DELETE requests is not interoperable.

Although request message framing is independent of the method used, content received in a DELETE request has no generally defined semantics, cannot alter the meaning or target of the request, and might lead some implementations to reject the request and close the connection because of its potential as a request smuggling attack

Dependency-Track Version

4.7.x

Dependency-Track Distribution

Container Image

Database Server

N/A

Database Server Version

No response

Browser

N/A

Checklist

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions