Re: PROPOSAL: i24 Requiring Allow in 405 Responses

OK,

here's what I'd like to do, based on Mark's summary and Stefan's latest 
proposal:

In the description of the Allow header, replace

  This field cannot prevent a client from trying other methods.
  However, the indications given by the Allow header field value
  SHOULD be followed. The actual set of allowed methods is defined
  by the origin server at the time of each request.

by

  This field cannot prevent a client from trying other methods.
  The published set of allowed methods is defined by the origin server at
  the time of each request. The absence of methods in this set has no
  defined semantics.

Also, in "Changes from RCF2616", add

  Relax the server requirement on the contents of the Allow header and
  remove requirement on clients to always trust the header value.

BR, Julian




Stefan Eissing wrote:
> 
> 
> Am 17.03.2008 um 07:43 schrieb Mark Nottingham:
> 
>> The proposal is to:
>>
>> * In p2 10.1, change "The actual set of allowed methods is defined by 
>> the origin server at the time of each request."  to  "The actual set 
>> of allowed methods is defined by the origin server at the time of each 
>> request, and may not necessarily include all (or any) methods that the 
>> server would actually allow in a request if presented."  (with normal 
>> editorial discretion)
> 
> How about:
> 
> "The published set of allowed methods is defined by the origin server at 
> the time of each request. The absence of methods in this set has no 
> defined semantics."
> 
> 
>>
>> * In p2 10.1, remove "However, the indications given by the Allow 
>> header field value SHOULD be followed."
> +1
> 
> -- 
> <green/>bytes GmbH, Hafenweg 16, D-48155 Münster, Germany
> Amtsgericht Münster: HRB5782
> 
> 
> 
> 
> 

Received on Monday, 17 March 2008 12:16:51 UTC