W3C home > Mailing lists > Public > public-webapi@w3.org > August 2007

Re: [xhr2] cross site non-GET requests and redirects

From: Anne van Kesteren <annevk@opera.com>
Date: Mon, 06 Aug 2007 15:31:39 +0200
To: "Jonas Sicking" <jonas@sicking.cc>
Cc: "Web APIs WG" <public-webapi@w3.org>, "Ian Hickson" <ian@hixie.ch>
Message-ID: <op.twm3u1m864w2qv@annevk-t60.oslo.opera.com>

On Wed, 01 Aug 2007 01:01:55 +0200, Jonas Sicking <jonas@sicking.cc> wrote:
> In the implementation I've written, the decision weather to check access  
> control headers is done by comparing the final uri with the requesting  
> uri. So if you're redirected back to the original server no  
> access-control check is done.

Ok, I've integrated this now in the XMLHttpRequest level 2 draft (support  
for cross-site XMLHttpRequest). I've not yet included Referer-Root:


Anne van Kesteren
Received on Monday, 6 August 2007 13:32:07 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 18:09:57 UTC