W3C home > Mailing lists > Public > ietf-http-wg@w3.org > January to March 2016

I-D Action: draft-ietf-httpbis-cookie-alone-00.txt

From: <internet-drafts@ietf.org>
Date: Tue, 23 Feb 2016 01:38:29 -0800
To: <i-d-announce@ietf.org>
Cc: ietf-http-wg@w3.org
Message-ID: <20160223093829.28424.17396.idtracker@ietfa.amsl.com>

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Hypertext Transfer Protocol of the IETF.

        Title           : Deprecate modification of 'secure' cookies from non-secure origins
        Author          : Mike West
	Filename        : draft-ietf-httpbis-cookie-alone-00.txt
	Pages           : 5
	Date            : 2016-02-23

Abstract:
   This document updates RFC6265 by removing the ability for a non-
   secure origin to set cookies with a 'secure' flag, and to overwrite
   cookies whose 'secure' flag is set.  This deprecation improves the
   isolation between HTTP and HTTPS origins, and reduces the risk of
   malicious interference.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-httpbis-cookie-alone/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-httpbis-cookie-alone-00


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/
Received on Tuesday, 23 February 2016 09:38:58 UTC

This archive was generated by hypermail 2.3.1 : Tuesday, 22 March 2016 12:47:11 UTC