review Access Control for Cross-site Requests?


I saw you worked on JSONRequest and have done a fair amount of security  
research into Web browsers, etc. Any chance you could review the stuff  
we're planning for XMLHttpRequest Level 2 and other protocols (such as  
server-sent events, XSLT, and XBL 2.0):

These documents are still changing and feedback is welcome on for the former and for the  
latter (in due course these activities will be merged under a single WG if  
all goes well). You can also e-mail me directly if that's more convenient,  
although in that case I'd prefer if you cc'ed a public mailing list, such  
as as I've done here.

Kind regards,

Anne van Kesteren

Received on Saturday, 2 February 2008 10:59:41 UTC