On Mar 10, 2006, at 3:08 PM, Mark Nottingham wrote: > a) Is the intent of the first SHOULD to allow credential caching > (e.g., similar to [1]) in intermediaries? No, the intent is to allow credential caching in user agents (the only creatures to whom Authorization applies). The rest of the section you quoted is irrelevant overspecification of the simple fact that responses to a request containing Authorization are not shared-cacheable unless explicitly made so by the origin server header fields (that are more than adequately defined elsewhere, making those additions here confusing). ....RoyReceived on Saturday, 11 March 2006 19:39:14 GMT
This archive was generated by hypermail 2.2.0+W3C-0.50 : Tuesday, 2 June 2009 18:22:14 GMT