ietf
[Top] [All Lists]

Re: [websec] Last Call: <draft-ietf-websec-origin-04.txt> (The Web Origin Concept) to Proposed Standard

2011-09-06 10:07:23
On Fri, Sep 2, 2011 at 3:26 AM, Julian Reschke 
<julian(_dot_)reschke(_at_)gmx(_dot_)de> wrote:
On 2011-09-02 12:20, Adam Barth wrote:
I replied to Julian's message on a W3C list.  Julian, is there more
discussion you'd like to have about these points?
...

Well, as discussed, the syntax of the Origin header makes it hard to detect
errors which happen when multiple instances get folded into one; see
<http://greenbytes.de/tech/webdav/draft-ietf-httpbis-p2-semantics-latest.html#considerations.for.creating.header.fields>
-- but I fear it's too late to fix this?

Unfortunately, yes.  Adding quotes would break the large number of
folks using already using this header.

Adam
_______________________________________________
Ietf mailing list
Ietf(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/ietf

<Prev in Thread] Current Thread [Next in Thread>