The document http://tools.ietf.org/html/draft-abarth-origin proposes a new HTTP header and rules for its use as a way of addressing Cross-Site Request Forgery (CSRF) attacks. This was part of the HTML5 work in WhatWG and W3C HTML working group. Is there's a better venue for discussion of this draft than ietf-http-wg@w3.org? Larry -- http://larry.masinter.netReceived on Thursday, 22 January 2009 17:33:52 GMT
This archive was generated by hypermail 2.2.0+W3C-0.50 : Monday, 7 December 2009 10:38:35 GMT