Re: The HTTP Origin Header (draft-abarth-origin)

Hi Larry,

As I responded to Ian, I think here is at least as appropriate as  
elsewhere.

Cheers,


On 23/01/2009, at 4:33 AM, Larry Masinter wrote:

> The document  http://tools.ietf.org/html/draft-abarth-origin
> proposes a new HTTP header and rules for its use as a way of  
> addressing
> Cross-Site Request Forgery (CSRF) attacks. This was part of the
> HTML5 work in WhatWG and W3C HTML working group.
>
> Is there's a better venue for discussion of this draft
> than ietf-http-wg@w3.org?
>
>
>
> Larry
> -- 
> http://larry.masinter.net
>
>
>
>
>


--
Mark Nottingham     http://www.mnot.net/

Received on Thursday, 22 January 2009 23:54:28 UTC