- From: Github Notifications <do_not_reply@mnot.net>
- Date: Sun, 28 Jul 2019 00:45:26 +0000 (UTC)
- To: ietf-http-wg@w3.org
- Message-Id: <20190728004526.E1E22C0F8D@cloud.mnot.net>
Events without label "editorial" Issues ------ * httpwg/http-extensions (+6/-6/💬33) 6 issues created: - Request `Digest` validation (by ioggstream) https://github.com/httpwg/http-extensions/issues/874 - Use cases for Digest (by ioggstream) https://github.com/httpwg/http-extensions/issues/872 [digest-headers] - Enable Client Hints on first navigation request through HTTPSSVC (by yoavweiss) https://github.com/httpwg/http-extensions/issues/871 - Disentangle the DNS Check argument (by MikeBishop) https://github.com/httpwg/http-extensions/issues/869 [secondary-certs] - Relationship to SRI (by martinthomson) https://github.com/httpwg/http-extensions/issues/868 - Should the obsolescence of MD5 be stronger? (by tfpauly) https://github.com/httpwg/http-extensions/issues/867 14 issues received 33 new comments: - #867 Should the obsolescence of MD5 be stronger? (10 by ioggstream, LPardue, tfpauly) https://github.com/httpwg/http-extensions/issues/867 [digest-headers] - #848 Serializing sh-float is hard (5 by reschke, phluid61, martinthomson, bsdphk) https://github.com/httpwg/http-extensions/issues/848 [header-structure] - #716 Consider a `Sec-CH-` prefix for client hint headers (3 by reschke, yoavweiss) https://github.com/httpwg/http-extensions/issues/716 [client-hints] - #868 Relationship to SRI (2 by ioggstream, LPardue) https://github.com/httpwg/http-extensions/issues/868 [digest-headers] - #874 Request `Digest` validation (2 by ioggstream, LPardue) https://github.com/httpwg/http-extensions/issues/874 [digest-headers] - #782 define a URI reference type (2 by kazuho, tfpauly) https://github.com/httpwg/http-extensions/issues/782 [header-structure] - #821 Considering http_response_status (2 by martinthomson, alyssawilk) https://github.com/httpwg/http-extensions/issues/821 [proxy-status] - #700 Clarify behavior for multiple values for CH headers (1 by yoavweiss) https://github.com/httpwg/http-extensions/issues/700 [client-hints] - #786 Active vs. passive fingerprinting (1 by yoavweiss) https://github.com/httpwg/http-extensions/issues/786 [client-hints] - #852 Create a threat model for `Digest` header. (1 by ioggstream) https://github.com/httpwg/http-extensions/issues/852 [digest-headers] - #855 Shall we use sh-binary serialization for `id-sha` digest-algoritms? (1 by ioggstream) https://github.com/httpwg/http-extensions/issues/855 [digest-headers] - #828 Digest Headers: what about the other algorithms? (1 by ioggstream) https://github.com/httpwg/http-extensions/issues/828 [digest-headers] - #778 Cache header name (1 by tfpauly) https://github.com/httpwg/http-extensions/issues/778 [cache-header] - #767 Client-Hints exposes fingerprint values to additional parties and logging sensitive locations (1 by igrigorik) https://github.com/httpwg/http-extensions/issues/767 [client-hints] 6 issues closed: - Request `Digest` validation https://github.com/httpwg/http-extensions/issues/874 [digest-headers] - Should the obsolescence of MD5 be stronger? https://github.com/httpwg/http-extensions/issues/867 [digest-headers] - Client Hints doesn't distinguish clearly between request and response header fields https://github.com/httpwg/http-extensions/issues/761 [client-hints] - Key -> Variants https://github.com/httpwg/http-extensions/issues/730 [client-hints] - Clarify behavior for multiple values for CH headers https://github.com/httpwg/http-extensions/issues/700 [client-hints] - Shall we use sh-binary serialization for `id-sha` digest-algoritms? https://github.com/httpwg/http-extensions/issues/855 [digest-headers] * httpwg/http-core (+0/-1/💬17) 10 issues received 17 new comments: - #218 Disambiguate 403 Forbidden (4 by asbjornu, reschke, mnot) https://github.com/httpwg/http-core/issues/218 [discuss] [semantics] - #128 Quoted cache-control directives (2 by reschke, MattMenke2) https://github.com/httpwg/http-core/issues/128 [caching] [discuss] - #212 byte-range-set definition allows OWS but probably doesn't work in practice (2 by royfielding, mnot) https://github.com/httpwg/http-core/issues/212 [discuss] [semantics] - #48 415 and Accept (2 by jsha, reschke) https://github.com/httpwg/http-core/issues/48 [semantics] - #215 field-value value space (2 by reschke, mnot) https://github.com/httpwg/http-core/issues/215 [discuss] [semantics] - #32 Duplicate header resolution in H1 (1 by reschke) https://github.com/httpwg/http-core/issues/32 [semantics] - #34 Use URL Standard for Location header (1 by mnot) https://github.com/httpwg/http-core/issues/34 [discuss] [semantics] - #169 URI length (1 by mnot) https://github.com/httpwg/http-core/issues/169 [discuss] [semantics] - #194 QUIC and https:// (1 by mnot) https://github.com/httpwg/http-core/issues/194 [discuss] [semantics] - #180 Clarify multiple `authorization` header behaviour or concatenation method (1 by mnot) https://github.com/httpwg/http-core/issues/180 [discuss] [semantics] 1 issues closed: - Method registry should include cacheability https://github.com/httpwg/http-core/issues/54 [erratum] [has-proposal] [semantics] Pull requests ------------- * httpwg/http-extensions (+6/-5/💬8) 6 pull requests submitted: - Detail dimensions of information exposure (by yoavweiss) https://github.com/httpwg/http-extensions/pull/879 - Remove Accept-CH-Lifetime (by igrigorik) https://github.com/httpwg/http-extensions/pull/878 [client-hints] - Obsolete ADLER-32 but don't forbid it. #828 (by ioggstream) https://github.com/httpwg/http-extensions/pull/877 - Fix: #832. Reference RFC6234 instead of FIPS180. (by ioggstream) https://github.com/httpwg/http-extensions/pull/876 - md5 must not be used (by ioggstream) https://github.com/httpwg/http-extensions/pull/875 - Add use cases section. (by ioggstream) https://github.com/httpwg/http-extensions/pull/873 3 pull requests received 8 new comments: - #866 Add an Alt-Svc extension (5 by martinthomson, yoavweiss, davidben) https://github.com/httpwg/http-extensions/pull/866 [client-hints] - #776 Add Sec- prefix to security considerations (2 by yoavweiss) https://github.com/httpwg/http-extensions/pull/776 [client-hints] - #879 Detail dimensions of information exposure (1 by yoavweiss) https://github.com/httpwg/http-extensions/pull/879 5 pull requests merged: - md5 must not be used https://github.com/httpwg/http-extensions/pull/875 - Clarify defined headers are response headers https://github.com/httpwg/http-extensions/pull/860 [client-hints] - Replace Key with Variants https://github.com/httpwg/http-extensions/pull/861 [client-hints] - [Client Hints] Replace ABNF with Structured Headers https://github.com/httpwg/http-extensions/pull/862 [client-hints] - Remove workaround for addstyle.sed bug. https://github.com/httpwg/http-extensions/pull/813 * httpwg/http-core (+1/-2/💬1) 1 pull requests submitted: - Disambiguate 403 Forbidden (#218) (by reschke) https://github.com/httpwg/http-core/pull/234 1 pull requests received 1 new comments: - #217 Refactor the range specifier grammar (1 by reschke) https://github.com/httpwg/http-core/pull/217 [discuss] [semantics] 2 pull requests merged: - Move the trailing CRLF from the line grammars into the message format (#62) https://github.com/httpwg/http-core/pull/232 - Get rid of "cacheable methods" https://github.com/httpwg/http-core/pull/229 Repositories tracked by this digest: ----------------------------------- * https://github.com/httpwg/http-extensions * https://github.com/httpwg/http-core
Received on Sunday, 28 July 2019 00:45:55 UTC