Re: XHR: restrictions on request headers

Ian Hickson wrote:
> ...
> But I would add one more. Authors are stupid. We shouldn't provide them 
> with features whose only possible use is for them to shoot themselves in 
> the foot. In other words, I would phrase the question not as "which 
> headers should we restrict", but "which headers should we allow", and only 
> allow those that have valid use cases.
> ...

How do you do that, when the set of headers with potential use cases is 
open-ended?

For instance, would "Destination", "Apply-To-Redirect-Ref" or "If" qualify?

Best regards, Julian

Received on Wednesday, 12 April 2006 00:02:33 UTC