Re: Op-sec simplification

On 1 November 2016 at 09:41, Mark Nottingham <mnot@mnot.net> wrote:
> Hold on -- are we layering in a new requirement to use the absolute form of the URL?

I don't know how we carry the scheme any other way.  We might try to
weasel this as being not "directly" to the origin server.

Maybe I should point out that this is in contradiction to that section.

(FWIW, the servers I'm aware of all handle absolute URIs well enough.)

Received on Monday, 31 October 2016 23:15:46 UTC