Formalizing the HTTP State Tokens proposal.

Way back in August, 2018, I started a thread [1] on a proposal to introduce
a client-controlled, origin-bound, HTTPS-only session identifier for
network-level state management [2].

I wasn't able to make it to IETF104, but I will be attending the HTTP
workshop next week. In the hopes of sparking some conversations there, I've
formalized the proposal as
https://tools.ietf.org/html/draft-west-http-state-tokens-00, clarifying
some pieces based on y'all's earlier feedback. I'm looking forward to your
feedback on, either here on the list, or at the workshop next week.

Thanks!

-mike

[1]: https://lists.w3.org/Archives/Public/ietf-http-wg/2018JulSep/0184.html
[2]: https://github.com/mikewest/http-state-tokens

Received on Thursday, 28 March 2019 10:14:59 UTC