summaryrefslogtreecommitdiff
path: root/searx/settings.yml
diff options
context:
space:
mode:
authorMarkus Heiser <markus.heiser@darmarit.de>2024-06-28 14:47:22 +0200
committerMarkus Heiser <markus.heiser@darmarIT.de>2025-08-26 08:20:56 +0200
commit92463ce6a7aacd366292a383373bebc32988b9c3 (patch)
treea6f2cebaacfb1dc1ec611732e9f00dd6c8070309 /searx/settings.yml
parenta369fe8f2915adc58ffcd611abe2e9af7d58411a (diff)
[doc] adds the missing documentation of the `server.method` settings.
TL;DR; For all the issues that comes with HTTP POST I recommend instance maintainers to switch to GET and lock the property in the preferences: ```yaml server: method: GET preferences: lock: - method ``` We don't want this in the defaults of the SearXNG distributions for the pros vs cons listed in this discussion: - https://github.com/searxng/searxng/pull/3619
Diffstat (limited to 'searx/settings.yml')
-rw-r--r--searx/settings.yml5
1 files changed, 3 insertions, 2 deletions
diff --git a/searx/settings.yml b/searx/settings.yml
index ca5e27df7..7d95e3d16 100644
--- a/searx/settings.yml
+++ b/searx/settings.yml
@@ -100,8 +100,9 @@ server:
image_proxy: false
# 1.0 and 1.1 are supported
http_protocol_version: "1.0"
- # POST queries are more secure as they don't show up in history but may cause
- # problems when using Firefox containers.
+ # POST queries are "more secure!" but are also the source of hard-to-locate
+ # annoyances, which is why GET may be better for end users and their browsers.
+ # see https://github.com/searxng/searxng/pull/3619
# Is overwritten by ${SEARXNG_METHOD}
method: "POST"
default_http_headers: