Re: Comments on: Access Control for Cross-site Requests

On 2007-12-20 01:59:12 +0000, Close, Tyler J. wrote:

> A simple proposal would be to send an OPTIONS request to "*"
> asking the server if it understands your new Referer-Root header.

With this proposal, the server would have to trust that the client
puts in the right Referrer-Root header.  It wouldn't have to trust
the client with its policies.

-- 
Thomas Roessler, W3C  <tlr@w3.org>

Received on Friday, 21 December 2007 20:24:57 UTC