Closed
Description
Motivation
There was an interesting question on Stackexchange:
Why is PUT Request not allowed by default in OWASP CoreRuleSet
And I couldn't find any relevant information (I checked both Coreruleset's documentation and the comment section of the rule)
Proposed solution
I think we should review the documentation and add the reasons for the decisions as to why IT IS there. May be it's "just" a historical reason, but I think we should inform users about our decisions.