[Bug 7032] Sandboxing and Referer

http://www.w3.org/Bugs/Public/show_bug.cgi?id=7032


Adam Barth <w3c@adambarth.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |w3c@adambarth.com




--- Comment #2 from Adam Barth <w3c@adambarth.com>  2009-06-18 00:50:34 ---
I think the thought process goes like this:

Premise 1) Referer can be used as a credential.
Premise 2) Sandboxed iframes should't get the credentials of their origin
(e.g., they get some unique origin).
-------------
Conclusion: Sandboxed iframes shouldn't get a Referer.

Do you disagree with one of the premises?


-- 
Configure bugmail: http://www.w3.org/Bugs/Public/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the QA contact for the bug.

Received on Thursday, 18 June 2009 00:50:40 UTC