Allowed headers for CSR (was: Accountability in [...])

Jonas Sicking wrote:
> If we can come up with an allowed header list I would be all for that. 
> [...] Please feel free to suggest additional headers.
> Preferably as a separate thread as this one is quite ranty, long and 
> covers a range of topics already. 
Hi Jonas, All,

My first post to the discussion list, but have been following the 
threads with great interest.

Anyway, at a minimum, I would expect that the various If-* headers that 
make a request conditional be included in the allowed header list.  
Similarly, Pragma and Cache-Control seem generally useful and in little 
danger of abuse. Comments? Others?


Regards,
Elias

Received on Wednesday, 20 February 2008 22:25:21 UTC