W3C home > Mailing lists > Public > ietf-http-wg@w3.org > January to March 2008

Re: HttpOnly

From: Carsten Bormann <cabo@tzi.org>
Date: Wed, 19 Mar 2008 09:35:51 +0100
Cc: Carsten Bormann <cabo@tzi.org>, <ietf-http-wg@w3.org>
Message-Id: <0925297A-93A8-41E9-9D53-C374B087DAE1@tzi.org>
To: "Jim Manico" <jim.manico@aspectsecurity.com>

On Mar 18 2008, at 20:55, Jim Manico wrote:

> What about http://www.ietf.org/rfc/rfc2965 ?

That is exactly what Daniel was talking about -- a standards-track  
spec that never made it into real life.

I think this needs to be marked as historic.
I also think the actual practice should be documented, and httponly is  
starting to become a part of that actual practice.

Gruesse, Carsten
Received on Wednesday, 19 March 2008 08:36:42 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Friday, 27 April 2012 06:50:37 GMT