W3C home > Mailing lists > Public > public-webapps@w3.org > April to June 2010

Re: Do we need to rename the Origin header?

From: Bil Corry <bil@corry.biz>
Date: Mon, 24 May 2010 23:30:16 -0700
Message-ID: <4BFB6E78.7020507@corry.biz>
To: Ian Hickson <ian@hixie.ch>
CC: Adam Barth <w3c@adambarth.com>, public-webapps@w3.org
Ian Hickson wrote on 5/24/2010 7:55 PM: 
> On Mon, 24 May 2010, Bil Corry wrote:
>> Adam Barth wrote on 7/16/2009 10:38 AM: 
>>> On Thu, Jul 16, 2009 at 8:47 AM, Bil Corry<bil@corry.biz> wrote:
>>>> I think you mean everything will NOT be privacy-sensitive except non-XHR GETs.
>>> I don't think we've quite settled on exactly what will be privacy
>>> sensitive.  It's most likely that POSTs and XHR will not be and that
>>> hyperlinks and image loads will be.  The goal is to harmonize with the
>>> Mozilla proposal.
>> I haven't been following the progress of this, has "privacy-sensitive" been defined in HTML5 yet?
> Yes.
>> The only reference I could find was in "2.6 Fetching Resources":
>> ---8<---
>> For the purposes of the Origin  header, if the fetching algorithm was explicitly initiated from an origin, then the origin that initiated the HTTP request is origin. Otherwise, this is a request from a "privacy-sensitive" context. [ORIGIN]
>> (from: http://www.whatwg.org/specs/web-apps/current-work/multipage/urls.html#fetching-resources)
>> --->8---
> That is the definition.

To clarify, the Origin header is sent for all requests now, except those that don't have an origin?  The Origin header is sent for GET, POST, XHR, and CORS?

- Bil
Received on Tuesday, 25 May 2010 06:30:56 UTC

This archive was generated by hypermail 2.3.1 : Friday, 27 October 2017 07:26:25 UTC