Re: Redirection MUST NOTs

On Tue, 4 Nov 2003, Mark Baker wrote:

>
> On Tue, Nov 04, 2003 at 11:00:42AM -0800, David Morris wrote:
> > What you propose requires a change to client behavior in a way that
> > potentially reduces the integrity of the user interaction for all sites
> > because you have a specific site you believe has a valid reason for
> > allowing handling the redirect w/o user interaction.
>
> Not at all.  My proposal doesn't require that any client change
> behaviour (as they'd still conform to a "SHOULD NOT" requirement).
> It just asks that new clients be permitted to auto-redirect if
> they have a very good reason to do so.

Without a protocol based reason for the client to alter its behavior,
there is no reason to even use "SHOULD NOT" in the HTTP specification. To
achieve the intended user protection, the base protocol needs to preclude
auto-redirect.

Dave Morris

Received on Tuesday, 4 November 2003 18:24:34 UTC