For the complete documentation index, see llms.txt. This page is also available as Markdown.

HTTP Method Spoofing

Although we have access to all the HTTP verbs, modern browsers still only support GET and POST. With ColdBox and HTTP Method Spoofing, you can take advantage of all the HTTP verbs in your web forms.

By convention, ColdBox will look for an _method field in the FORM scope. If one exists, and the transport-level request is a POST, its value is used as the HTTP method instead of POST — for PUT, PATCH, or DELETE targets only. For instance, the following block of code would execute with the DELETE action instead of the POST action:

<cfoutput>
<form method="POST" action="#event.buildLink( 'posts/#prc.post.getId()#' )#">
    <input type="hidden" name="_method" value="DELETE" />
    <button type="submit">Delete</button>
</form>
</cfoutput>

You can manually add these _method fields yourselves, or you can take advantage of ColdBox's HTML Helper startForm() method. Just pass the method you like, we will take care of the rest:

<cfoutput>
#html.startForm( action = "posts.#prc.post.getId()#", method="DELETE" )#
    #html.submitButton( name = "Delete", class = "btn btn-danger" )#
#html.endForm()#
</cfoutput>

Original method

_method

event.getHTTPMethod() result

GET

DELETE

GET — override ignored

HEAD

DELETE

HEAD — override ignored

POST

DELETE

DELETE

POST

PUT

PUT

POST

PATCH

PATCH

POST

GET

POST — invalid override ignored

Getting the Original Method

event.getHTTPMethod() returns the effective method after spoofing is applied - the one your routes and withVerbs()/allowedMethods checks match against. If you need the raw, un-spoofed transport-level method instead (for logging, auditing, or a security interceptor), use event.getOriginalHTTPMethod():

Last updated

Was this helpful?