Weekly github digest (HTTP Activity Summary)

Events without label "editorial"

Issues
------
* httpwg/http-core (+19/-7/💬49)
  19 issues created:
  - Semantics: 11.6.2 Authentication (by wenbozhu)
    https://github.com/httpwg/http-core/issues/745 
  - Semantics: 9.2.2 Idempotent Methods (by wenbozhu)
    https://github.com/httpwg/http-core/issues/744 
  - Semantics: 7.8 Upgrade (by wenbozhu)
    https://github.com/httpwg/http-core/issues/743 
  - Semantics: 7.6.3 typo? (by wenbozhu)
    https://github.com/httpwg/http-core/issues/742 
  - Semantics: full-duplex related semantics ... (by wenbozhu)
    https://github.com/httpwg/http-core/issues/741 
  - Semantics: 6 Message Abstraction (by wenbozhu)
    https://github.com/httpwg/http-core/issues/740 
  - Semantics 3.3 Connections ... (by wenbozhu)
    https://github.com/httpwg/http-core/issues/739 
  - Semantics 2.4 Error Handling   (by wenbozhu)
    https://github.com/httpwg/http-core/issues/738 
  - SEMANTICS describes CONNECT in HTTP/1.1 terms (by MikeBishop)
    https://github.com/httpwg/http-core/issues/737 
  - Default port for CONNECT (by martinthomson)
    https://github.com/httpwg/http-core/issues/736 
  - Arbitrary limitation on authentication parameters (by mnot)
    https://github.com/httpwg/http-core/issues/733 [semantics] 
  - Cache poisoning doesn't just affect shared caches (by martinthomson)
    https://github.com/httpwg/http-core/issues/730 
  - Identity of the proxy in the cache key (by martinthomson)
    https://github.com/httpwg/http-core/issues/729 
  - Define "cache key" (by martinthomson)
    https://github.com/httpwg/http-core/issues/728 
  - Why is Welch in the index? (by martinthomson)
    https://github.com/httpwg/http-core/issues/727 
  - What sort of message integrity are we concerned about? (by martinthomson)
    https://github.com/httpwg/http-core/issues/726 
  - TLS does not require clean close for resumption (by martinthomson)
    https://github.com/httpwg/http-core/issues/725 
  - Content-Length on requests (by martinthomson)
    https://github.com/httpwg/http-core/issues/723 
  - Default value for Host (by martinthomson)
    https://github.com/httpwg/http-core/issues/722 

  24 issues received 49 new comments:
  - #745 Semantics: 11.6.2 Authentication (1 by martinthomson)
    https://github.com/httpwg/http-core/issues/745 
  - #744 Semantics: 9.2.2 Idempotent Methods (1 by royfielding)
    https://github.com/httpwg/http-core/issues/744 [semantics] 
  - #743 Semantics: 7.8 Upgrade (1 by reschke)
    https://github.com/httpwg/http-core/issues/743 [semantics] 
  - #742 Semantics: 7.6.3 typo? (2 by reschke, royfielding)
    https://github.com/httpwg/http-core/issues/742 [semantics] 
  - #741 Semantics: full-duplex related semantics ... (1 by wenbozhu)
    https://github.com/httpwg/http-core/issues/741 
  - #740 Semantics: 6 Message Abstraction (1 by reschke)
    https://github.com/httpwg/http-core/issues/740 [semantics] 
  - #737 SEMANTICS describes CONNECT in HTTP/1.1 terms (1 by royfielding)
    https://github.com/httpwg/http-core/issues/737 [semantics] 
  - #736 Default port for CONNECT (4 by kazuho, mnot, royfielding)
    https://github.com/httpwg/http-core/issues/736 [semantics] 
  - #733 Arbitrary limitation on authentication parameters (4 by mnot, reschke)
    https://github.com/httpwg/http-core/issues/733 [semantics] 
  - #729 Identity of the proxy in the cache key (1 by mnot)
    https://github.com/httpwg/http-core/issues/729 
  - #727 Why is Welch in the index? (1 by martinthomson)
    https://github.com/httpwg/http-core/issues/727 
  - #723 Content-Length on requests (1 by royfielding)
    https://github.com/httpwg/http-core/issues/723 
  - #722 Default value for Host (3 by martinthomson, royfielding)
    https://github.com/httpwg/http-core/issues/722 
  - #715 Unknown preconditions aren't safe (1 by royfielding)
    https://github.com/httpwg/http-core/issues/715 [semantics] 
  - #713 Should Charset mention UTF-8 (4 by annevk, reschke, royfielding)
    https://github.com/httpwg/http-core/issues/713 
  - #710 Realm is under-specified (1 by reschke)
    https://github.com/httpwg/http-core/issues/710 
  - #709 Important notes regarding Referer (2 by martinthomson, royfielding)
    https://github.com/httpwg/http-core/issues/709 
  - #704 Content-Length and Transfer-Encoding coexistence (2 by martinthomson, reschke)
    https://github.com/httpwg/http-core/issues/704 
  - #703 Is a prohibition against mixed line termination a requirement? (1 by reschke)
    https://github.com/httpwg/http-core/issues/703 
  - #700 Messages aren't always self-descriptive (1 by royfielding)
    https://github.com/httpwg/http-core/issues/700 
  - #697 Whitespace is not removed from field values in HTTP/2 or HTTP/3 (3 by mnot, reschke)
    https://github.com/httpwg/http-core/issues/697 [semantics] 
  - #683 field-value production rules out CTL characters, but these are common in the wild (9 by njsmith, reschke, royfielding)
    https://github.com/httpwg/http-core/issues/683 [semantics] 
  - #682 Field section gone? (2 by MikeBishop, mnot)
    https://github.com/httpwg/http-core/issues/682 [semantics] 
  - #681 Should -messaging obsolete RFC 1945 (1 by mnot)
    https://github.com/httpwg/http-core/issues/681 [h1-messaging] 

  7 issues closed:
  - Semantics: 7.6.3 typo? https://github.com/httpwg/http-core/issues/742 [semantics] 
  - Semantics: 6 Message Abstraction https://github.com/httpwg/http-core/issues/740 [semantics] 
  - status-code parsing https://github.com/httpwg/http-core/issues/684 [has-proposal] [semantics] 
  - Field section gone? https://github.com/httpwg/http-core/issues/682 [semantics] 
  - Content-Length on requests https://github.com/httpwg/http-core/issues/723 
  - URI-ID or DNS-ID? https://github.com/httpwg/http-core/issues/680 [semantics] 
  - Why is Welch in the index? https://github.com/httpwg/http-core/issues/727 

* httpwg/http-extensions (+8/-4/💬27)
  8 issues created:
  - RFC 6265bis: Set-Cookie parsing algorithm should enforce more of the syntax requirements (by chlily1)
    https://github.com/httpwg/http-extensions/issues/1399 
  - digest headers: HTTP Digest Algorithm Values registration rules (by seanturner)
    https://github.com/httpwg/http-extensions/issues/1394 
  - digest-headers: update HTTP Digest Algorithms Values registry reference (by seanturner)
    https://github.com/httpwg/http-extensions/issues/1393 
  - digest-headers: refer to 6151/6194 for md5/sha1 deprecation (by seanturner)
    https://github.com/httpwg/http-extensions/issues/1392 
  - RFC6265bis: Mention considering domain a-v length when sorting the cookie-list (by miketaylr)
    https://github.com/httpwg/http-extensions/issues/1391 
  - Signature: Invalid SFV format for Signature-Input field (by Jxck)
    https://github.com/httpwg/http-extensions/issues/1390 
  - Variants: Invalid SFV format for Variants field (by Jxck)
    https://github.com/httpwg/http-extensions/issues/1389 
  - Invalid SFV format - Digest  (by Jxck)
    https://github.com/httpwg/http-extensions/issues/1388 

  14 issues received 27 new comments:
  - #1394 digest headers: HTTP Digest Algorithm Values registration rules (1 by LPardue)
    https://github.com/httpwg/http-extensions/issues/1394 
  - #1393 digest-headers: update HTTP Digest Algorithms Values registry reference (4 by LPardue, reschke, seanturner)
    https://github.com/httpwg/http-extensions/issues/1393 [digest-headers] 
  - #1392 digest-headers: refer to 6151/6194 for md5/sha1 deprecation (1 by LPardue)
    https://github.com/httpwg/http-extensions/issues/1392 
  - #1391 RFC6265bis: Mention considering domain a-v length when sorting the cookie-list (1 by miketaylr)
    https://github.com/httpwg/http-extensions/issues/1391 [6265bis] 
  - #1388 Digest: Invalid SFV format for Digest field (3 by Jxck, LPardue)
    https://github.com/httpwg/http-extensions/issues/1388 
  - #1363 digest-headers: support vs SRI (2 by LPardue, ioggstream)
    https://github.com/httpwg/http-extensions/issues/1363 [digest-headers] 
  - #1340 [6265bis] Clarification on cookie size limits (1 by miketaylr)
    https://github.com/httpwg/http-extensions/issues/1340 [6265bis] 
  - #1337 [6265bis] Align on HTML terminology for origins (1 by miketaylr)
    https://github.com/httpwg/http-extensions/issues/1337 [6265bis] 
  - #1332 rfc6265bis empty domain attribute (3 by chlily1, miketaylr)
    https://github.com/httpwg/http-extensions/issues/1332 [6265bis] 
  - #1289 6265bis doesn't have an opinion on localhost cookies (1 by sbingler)
    https://github.com/httpwg/http-extensions/issues/1289 [6265bis] 
  - #1241 Incrementally Better Cookies vs RFC6265bis (2 by annevk, chlily1)
    https://github.com/httpwg/http-extensions/issues/1241 [6265bis] 
  - #1136 rfc6265bis UA requirements and WPT mismatch (5 by chlily1, essen, miketaylr)
    https://github.com/httpwg/http-extensions/issues/1136 [6265bis] 
  - #773 Correct behaviour for a POST-redirect-GET when using SameSite=Lax (1 by miketaylr)
    https://github.com/httpwg/http-extensions/issues/773 [6265bis] [samesite] 
  - #748 header field (1 by ioggstream)
    https://github.com/httpwg/http-extensions/issues/748 [bcp56bis] 

  4 issues closed:
  - RFC6265bis: Mention considering domain a-v length when sorting the cookie-list https://github.com/httpwg/http-extensions/issues/1391 [6265bis] 
  - Create a threat model for `Digest` header. https://github.com/httpwg/http-extensions/issues/852 [digest-headers] 
  - digest-headers: refer to 6151/6194 for md5/sha1 deprecation https://github.com/httpwg/http-extensions/issues/1392 [digest-headers] 
  - Digest: Invalid SFV format for Digest field https://github.com/httpwg/http-extensions/issues/1388 

* httpwg/http2-spec (+3/-6/💬3)
  3 issues created:
  - characters allowed in field values (by reschke)
    https://github.com/httpwg/http2-spec/issues/815 
  - Interim responses are messages (by martinthomson)
    https://github.com/httpwg/http2-spec/issues/812 
  - A wide diagram might be made narrower (by martinthomson)
    https://github.com/httpwg/http2-spec/issues/810 

  1 issues received 3 new comments:
  - #815 characters allowed in field values (3 by Lukasa, afrind, reschke)
    https://github.com/httpwg/http2-spec/issues/815 

  6 issues closed:
  - Midders or multiple trailers https://github.com/httpwg/http2-spec/issues/780 
  - The requirement to use SNI is not possible always https://github.com/httpwg/http2-spec/issues/792 
  - Integrate TLS 1.3 updates https://github.com/httpwg/http2-spec/issues/774 
  - Defer to core HTTP for 421 status code https://github.com/httpwg/http2-spec/issues/802 
  - Connection headers and proxies https://github.com/httpwg/http2-spec/issues/804 
  - "Payload" is too heavily overloaded https://github.com/httpwg/http2-spec/issues/803 



Pull requests
-------------
* httpwg/http-core (+7/-7/💬12)
  7 pull requests submitted:
  - Attempt a rewrite of message integrity text (by martinthomson)
    https://github.com/httpwg/http-core/pull/735 
  - Fixes for TLS connection closure (by martinthomson)
    https://github.com/httpwg/http-core/pull/734 
  - Make Host directly mandatory (by martinthomson)
    https://github.com/httpwg/http-core/pull/732 
  - Clearer requirements about delineation of requests (by martinthomson)
    https://github.com/httpwg/http-core/pull/731 
  - Network congestion or server load (by martinthomson)
    https://github.com/httpwg/http-core/pull/724 
  - Cite conditional requests in 412 definition (by martinthomson)
    https://github.com/httpwg/http-core/pull/721 
  - Clarify status code range (fixes #684) (by reschke)
    https://github.com/httpwg/http-core/pull/717 [semantics] 

  4 pull requests received 12 new comments:
  - #734 Fixes for TLS connection closure (1 by martinthomson)
    https://github.com/httpwg/http-core/pull/734 
  - #724 Network congestion or server load (1 by martinthomson)
    https://github.com/httpwg/http-core/pull/724 
  - #717 Clarify status code range (fixes #684) (9 by annevk, mnot, reschke, royfielding)
    https://github.com/httpwg/http-core/pull/717 [semantics] 
  - #707 Origin servers might support CONNECT (1 by martinthomson)
    https://github.com/httpwg/http-core/pull/707 

  7 pull requests merged:
  - Attempt a rewrite of message integrity text
    https://github.com/httpwg/http-core/pull/735 
  - Clarify status code range (fixes #684)
    https://github.com/httpwg/http-core/pull/717 [semantics] 
  - Clearer requirements about delineation of requests
    https://github.com/httpwg/http-core/pull/731 
  - IP address reference identities
    https://github.com/httpwg/http-core/pull/685 
  - Try to better define "strong" encryption
    https://github.com/httpwg/http-core/pull/695 
  - A content-type converts abstract data into bits
    https://github.com/httpwg/http-core/pull/702 [semantics] 
  - Cite conditional requests in 412 definition
    https://github.com/httpwg/http-core/pull/721 

* httpwg/http-extensions (+4/-3/💬15)
  4 pull requests submitted:
  - Update 54Replace normative references with brace notation. See #1250. (by ioggstream)
    https://github.com/httpwg/http-extensions/pull/1398 
  - Fix: #1392. Reference RFC 6515 and 6194 for deprecating md5 and sha1. (by ioggstream)
    https://github.com/httpwg/http-extensions/pull/1397 
  - Fix: #1395. Obsolete RFC3230. (by ioggstream)
    https://github.com/httpwg/http-extensions/pull/1396 
  - Limit more error types to responses generated by intermediaries. (by PiotrSikora)
    https://github.com/httpwg/http-extensions/pull/1387 

  7 pull requests received 15 new comments:
  - #1397 Fix: #1392. Reference RFC 6515 and 6194 for deprecating md5 and sha1. (2 by ioggstream)
    https://github.com/httpwg/http-extensions/pull/1397 [digest-headers] 
  - #1376 Fix: #1357. Clarify Digest+HEAD. (2 by ioggstream, reschke)
    https://github.com/httpwg/http-extensions/pull/1376 [digest-headers] 
  - #1354 digest: fix SRI section ref (1 by ioggstream)
    https://github.com/httpwg/http-extensions/pull/1354 [digest-headers] 
  - #1335 Fix: #852. Mention resource consumption. (3 by LPardue, ioggstream)
    https://github.com/httpwg/http-extensions/pull/1335 [digest-headers] 
  - #910 Use payload body. (1 by ioggstream)
    https://github.com/httpwg/http-extensions/pull/910 [bcp56bis] 
  - #756 bcp56bis: consistently use "header field" (resolves #748) (1 by ioggstream)
    https://github.com/httpwg/http-extensions/pull/756 [bcp56bis] 
  - #690 Adding a note about 303 See Other (5 by evert, ioggstream, reschke)
    https://github.com/httpwg/http-extensions/pull/690 [bcp56bis] 

  3 pull requests merged:
  - Fix: #852. Mention resource consumption.
    https://github.com/httpwg/http-extensions/pull/1335 [digest-headers] 
  - Fix: #1392. Reference RFC 6515 and 6194 for deprecating md5 and sha1.
    https://github.com/httpwg/http-extensions/pull/1397 [digest-headers] 
  - Fix: #1395. Obsolete RFC3230.
    https://github.com/httpwg/http-extensions/pull/1396 

* httpwg/http2-spec (+4/-9/💬4)
  4 pull requests submitted:
  - fix IETF area name (by reschke)
    https://github.com/httpwg/http2-spec/pull/816 
  - Reduce the width of the upgrade diagram. (by Lukasa)
    https://github.com/httpwg/http2-spec/pull/814 
  - Clarify that PRIORITY does not close streams. (by Lukasa)
    https://github.com/httpwg/http2-spec/pull/813 
  - First pass on references to updated documents (by martinthomson)
    https://github.com/httpwg/http2-spec/pull/811 

  2 pull requests received 4 new comments:
  - #814 Reduce the width of the upgrade diagram. (1 by martinthomson)
    https://github.com/httpwg/http2-spec/pull/814 
  - #809 fix IETF area name (3 by martinthomson, reschke)
    https://github.com/httpwg/http2-spec/pull/809 

  9 pull requests merged:
  - Clarify that PRIORITY does not close streams.
    https://github.com/httpwg/http2-spec/pull/813 
  - Reduce the width of the upgrade diagram.
    https://github.com/httpwg/http2-spec/pull/814 
  - Clarifications for trailers
    https://github.com/httpwg/http2-spec/pull/799 
  - Condition SNI requirement more carefully
    https://github.com/httpwg/http2-spec/pull/798 
  - Extensions defining pseudo-header fields
    https://github.com/httpwg/http2-spec/pull/796 
  - Changes for TLS 1.3
    https://github.com/httpwg/http2-spec/pull/797 
  - Remove definition of 421 and point to core.
    https://github.com/httpwg/http2-spec/pull/808 
  - Defer to the core spec for connection-specific headers
    https://github.com/httpwg/http2-spec/pull/807 
  - Remove use of "payload" for message bodies.
    https://github.com/httpwg/http2-spec/pull/806 


Repositories tracked by this digest:
-----------------------------------
* https://github.com/httpwg/http-core
* https://github.com/httpwg/http-extensions
* https://github.com/httpwg/http2-spec

Received on Sunday, 7 February 2021 07:36:47 UTC