W3C home > Mailing lists > Public > public-webappsec@w3.org > January 2015

Re: [CSP] URI/IRI normalization and comparison

From: Anne van Kesteren <annevk@annevk.nl>
Date: Wed, 21 Jan 2015 13:33:14 +0100
Message-ID: <CADnb78iZ8TD6GRr6QHM+Kdq4iWor0MedaPJ2Xa1RKsZq61Vv_g@mail.gmail.com>
To: Mike West <mkwst@google.com>
Cc: Brian Smith <brian@briansmith.org>, "public-webappsec@w3.org" <public-webappsec@w3.org>
On Wed, Jan 21, 2015 at 1:21 PM, Mike West <mkwst@google.com> wrote:
> What seems ok? Reverting the addition of IPv6 grammar, or changing our
> matching algorithms to match IPv6?

It seems okay to me to not support IP address matching and require
domain names. If you do want to support it you'll have to make sure
that you normalize both sides (or parse both sides into a data model
you can compare).

Received on Wednesday, 21 January 2015 12:33:37 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 18:54:44 UTC