Re: [access-control] Potential security problem (port should be auto-restricted)

On 2007-10-03 23:08:59 +0000, Ian Hickson wrote:

> On Wed, 3 Oct 2007, Jonas Sicking wrote:

> > Hmm.. this isn't really ideal I think as it would be very easy to forget 
> > to add the 'http://' part and inadvertently end up in the situation Ian 
> > describes. Could we use the default port of the requesting scheme 
> > instead?

> That seems fine to me.

+1

-- 
Thomas Roessler, W3C  <tlr@w3.org>

Received on Thursday, 4 October 2007 00:08:19 UTC