The reality is though that even with how screwed up the spec is HTTP is an enormous success. It got more complex as time went on but in the early days it was fairly simple.
Now contrast that with SAML, OAuth2, WS-Security (anyone care to add any others?) and you can see how much of a trainwreck we avoided.
Now contrast that with SAML, OAuth2, WS-Security (anyone care to add any others?) and you can see how much of a trainwreck we avoided.