You must make a POST request from clients (using an AJAX or POSTing form). This is because if you allow something to remove GET, your service will be vulnerable to CSRF. Someone will send your administrator an email or something else and you will have problems.
source share