Re: The HTTP Origin Header (draft-abarth-origin)

On Jan 22, 2009, at 4:55 PM, Mark Nottingham wrote:

> Ah, I missed the clause "where it is currently not set at all."
>
> Why would even that change be necessary? AIUI browsers sent no  
> value when the request wasn't sourced from a particular HTTP URI;  
> that's information that's valuable to the server (as Adrien points  
> out).

Er, right, I should have limited it to the https case where
nothing is sent for (what I've always considered bogus)
privacy reasons.

....Roy

Received on Friday, 23 January 2009 01:16:59 UTC