W3C home > Mailing lists > Public > public-appformats@w3.org > April 2008

Re: Update to Access Control for Cross-site Requests

From: Jonas Sicking <jonas@sicking.cc>
Date: Mon, 07 Apr 2008 16:31:23 -0700
Message-ID: <47FAAECB.4040902@sicking.cc>
To: Anne van Kesteren <annevk@opera.com>
CC: "WAF WG (public)" <public-appformats@w3.org>

Anne van Kesteren wrote:
> 
> I have updated the editor's draft of the Access Control for Cross-site 
> Requests specification to include support for  HTTP headers as per my 
> proposal earlier:
> 
>   http://www.w3.org/mid/op.t6ug2pld64w2qv@annevk-t60.oslo.opera.com
>   http://dev.w3.org/2006/waf/access-control/
> 
> Nothing else has changed because no other changes have been proposed.
> 
> I think we should be able to go to Last Call now.

I do not think we are ready to go into Last Call. There is a major 
outstanding issue, which is if cookies and auth headers should be 
included. Implementation wise this is easy to change, but it 
significantly changes the semantics of the spec, so I think it's an 
issue we need to find a resolution for first.

I'm all for publishing another draft though.

/ Jonas
Received on Monday, 7 April 2008 23:33:40 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Monday, 7 April 2008 23:33:41 GMT