W3C home > Mailing lists > Public > ietf-http-wg@w3.org > July to September 2014

Re: consensus on :query ?

From: Martin Thomson <martin.thomson@gmail.com>
Date: Mon, 21 Jul 2014 06:20:27 -0700
Message-ID: <CABkgnnVcFzuoUCwSY03=a-MCS1v3BtNeGL+65HqPDf4awCAPRg@mail.gmail.com>
To: Willy Tarreau <w@1wt.eu>
Cc: Roberto Peon <grmocg@gmail.com>, Poul-Henning Kamp <phk@phk.freebsd.dk>, Phil Hunt <phil.hunt@oracle.com>, Mark Nottingham <mnot@mnot.net>, HTTP Working Group <ietf-http-wg@w3.org>
On 21 July 2014 00:53, Willy Tarreau <w@1wt.eu> wrote:
>
> I'm not sure what you mean, we're speaking about having a single :query
> for whatever follows the question mark, right ? If so, all the params
> must be tried as a single block.

Yes, but there could be cases where the combination of path and query
contain sufficiently high entropy in combination, but one or other
contains insufficient entropy on its own to resist guessing attacks.
Received on Monday, 21 July 2014 13:20:55 UTC

This archive was generated by hypermail 2.3.1 : Wednesday, 30 March 2016 09:57:09 UTC