W3C home > Mailing lists > Public > ietf-http-wg@w3.org > April to June 2012

Re: WGLC #349: "strength"

From: Julian Reschke <julian.reschke@gmx.de>
Date: Thu, 31 May 2012 15:35:40 +0200
Message-ID: <4FC773AC.8030402@gmx.de>
To: Mark Nottingham <mnot@mnot.net>
CC: HTTP Working Group <ietf-http-wg@w3.org>
On 2012-05-31 14:20, Mark Nottingham wrote:
> <http://trac.tools.ietf.org/wg/httpbis/trac/ticket/349>
>
> Proposal: change
>
>>     Both the Authorization field value and the Proxy-Authorization field
>>     value consist of credentials containing the authentication
>>     information of the client for the realm of the resource being
>>     requested.  The user agent MUST choose to use one of the challenges
>>     with the strongest auth-scheme it understands and request credentials
>>     from the user based upon that challenge.
>
>
> to
>
> """
> Both the Authorization field value and the Proxy-Authorization field value contain the client's credentials for the realm of the resource being requested, based upon a challenge received from the server (possibly at some point in the past). When creating their values, the user agent ought to do so by selecting the challenge with what it considers to be the most secure auth-scheme that it understands, obtaining credentials from the user as appropriate.
> """

Sounds good to me.

Best regards, Julian
Received on Thursday, 31 May 2012 13:36:18 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Thursday, 31 May 2012 13:36:29 GMT