View Single Post
Old 4 Nov 2022, 04:10 AM   #7
JeremyNicoll
Essential Contributor
 
Join Date: Dec 2017
Location: Scotland
Posts: 484
Quote:
Originally Posted by unreal View Post
I'm not expecting to have Sieve/FM run arbitrary code on their servers, just letting me "poke" a webhook URL through get/post request.
It's not arbitrary code, from your point of view... but if FM had a mechanism where you could do what /you/ want, it would also allow other people to do arbitrary other things.

Where do you suppose a GET request would put the data returned by the remote server?

Suppose they allowed POST requests? Then their server would be attempting to update locations on third-party webservers. Can you not see that that could be misused, and perhaps cause FM to have their servers blocked?
JeremyNicoll is offline   Reply With Quote