Re: Exclude header

> 1 -- The Policy Header: will this be included in each page served from a
> site, or does it refer to a *session* (i.e. as defined by cookies)?

The idea is for it to be returned with every HTTP response.

> 2 -- Do the Prefix and Exclude headers refer to other documents that are
> incorporated into the page on which they appear, i.e. can these, when
used,
> exclude such things as inline graphics? (I think I'm asking the definition
> of *document* in this context.)

They refer to other documents on the site. Some of these documents
may be embedded objects, others not. They may be used for example,
to indicate up front that an entire site, or an entire directory within
the site, follows the same policy. They might also be used to indicate
that a certain directory on the site follows a different policy from the
rest of the site.

It is important to note that a policy does not automatically apply
to embedded content (inline graphics, frames, etc.).

Regards,

Lorrie Cranor
P3P Specification Working Group Chair

Received on Wednesday, 12 April 2000 17:18:34 UTC