https://justice-reaper.github.io/posts/Access-Control-Lab-11/
Method-based access control can be circumvented - Justice-Reaper