Forum OpenACS Q&A: Re: RFC: Security policy for OpenACS (Security hole in OpenACS 5.1!)

A couple people pointed out that making POST-only the default behavior for ad_form processing would break the redirect-for-login code, which resubmits the page with GET variables after logging in.