ISSUE-107: Should there be any recommendations for https->http form submissions? [Techniques]

ISSUE-107: Should there be any recommendations for https->http form submissions? [Techniques]

http://www.w3.org/2006/WSC/track/issues/

Raised by: Thomas Roessler
On product: Techniques

Per ACTION-289, I've updated the editor's draft to call out explicitly that we do not consider it a "change of security level" if a form on an HTTPS site is submitted by plain HTTP.

  @@Web Security Context@@
  Editor's Draft $Date: 2007/09/18 12:01:01 $ 
  
  http://www.w3.org/2006/WSC/drafts/rec/rewrite.html#change-redirects

The issue is whether we should be covering this situation.

Received on Tuesday, 18 September 2007 12:04:26 UTC