W3C home > Mailing lists > Public > whatwg@whatwg.org > September 2009

[whatwg] spec comments (websocket)

From: Wenbo Zhu <wenboz@google.com>
Date: Fri, 4 Sep 2009 17:01:34 -0700
Message-ID: <83c4e7ff0909041701u525010d8x874fb3816b359e07@mail.gmail.com>
re: http://tools.ietf.org/html/draft-hixie-thewebsocketprotocol-40
1) section 6:  "User agents should not close the Web Socket connection

Please clarify what "arbitrarily" means .. given there is no handshake for

2) section 7: "Servers that only accept input from one origin can just send
back that value in the "WebSocket-Origin" header, without bothering to check
the client's value."

I suppose servers should still verify the (single) origin to ensure it
matches .. Yes, the server simple echoes back the received origin

- Wenbo
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.whatwg.org/pipermail/whatwg-whatwg.org/attachments/20090904/fee0ec83/attachment.htm>
Received on Friday, 4 September 2009 17:01:34 UTC

This archive was generated by hypermail 2.3.1 : Monday, 13 April 2015 23:08:52 UTC