re: If your primary concern is information expose in server logs (why Iā€™m not sure, but okay), reconfigure your server to log less information. Done.

As a thought exercise, why should a RESTful architecture depend on HTTP ?


Sure, you could relegate HTTP to be a mere transport mechanism and implement your own "RESTful" protocol on top of that. Does that provide any advantage? Does it allow you to easily switch the transport layer to something else down the line? Is that a foreseeable requirement? Also see Inner-platform effect.

