On Fri, 08 Aug 2008 11:38:55 +0200, Jonas Sicking <jonas@sicking.cc> wrote: > String comparison is not going to be ok either way. The following two > origins are equivalent: > > http://www.foo.com > http://www.foo.com:80 My proposal was to treat those as non-equivalent. Basically, to require Access-Control-Allow-Origin to have the same value as Origin. (It seems that Ian has used this approach for WebSocket as well.) -- Anne van Kesteren <http://annevankesteren.nl/> <http://www.opera.com/>Received on Friday, 8 August 2008 09:44:23 GMT
This archive was generated by hypermail 2.2.0+W3C-0.50 : Monday, 7 December 2009 10:43:00 GMT