Re: Origin header for safe methods other than GET/HEAD, was: The HTTP Origin Header (draft-abarth-origin)

On Fri, Jan 23, 2009 at 12:30 AM, Julian Reschke <julian.reschke@gmx.de> wrote:
>   Whenever a user agent issues an HTTP request whose method is neither
>   "GET" nor "HEAD", the user agent MUST include exactly one HTTP header
>   named "Origin".
>
> What about other safe methods, such as PROPFIND, REPORT or SEARCH? Shouldn't
> the spec just say:
>
>   Whenever a user agent issues an HTTP request whose method is not
>   known to be safe (see ...), the user agent MUST include exactly
>   one HTTP header named "Origin".
>
> ?

Good point.  What should I cite as the authoritative list of safe methods?

Thanks for your feedback,
Adam

Received on Friday, 23 January 2009 17:15:41 UTC