Re: The HTTP Origin Header (draft-abarth-origin)

On Thu, Jan 22, 2009 at 5:46 PM, William A. Rowe, Jr.
<wrowe@rowe-clan.net> wrote:
> If you really wanted to solve this programmaticly, you would add a specific
> hash or noonce to identify the origin to itself...

This design rules out common use cases such as berkeley.facebook.com
POSTing a request to www.facebook.com.

Adam

Received on Friday, 23 January 2009 02:17:17 UTC