I agree that not specifying a HTTP method should be a blocking issue but that shouldn't be the case if you explicitly specify that both GET and POST are supported. For example the OpenID-Connect /userinfo endpoint should support both GET and POST requests according to the spec.
Thanks for the feedback. Could you raise your concern on the https://community.sonarsource.com/c/bug/fp[Community Forum] instead of here, as it's easier that using JIRA's comments? Thx