W3C home > Mailing lists > Public > public-webappsec@w3.org > May 2015

Re: [REFERRER] policy inheritance via javascript: URI and new document

From: Sid Stamm <sid@mozilla.com>
Date: Fri, 1 May 2015 12:47:37 -0400
Message-ID: <CAP=NJFO6EOArgVf48oTaVZ2ona7KQBQkrDChng6_dqKvOsFKMQ@mail.gmail.com>
To: Mike West <mkwst@google.com>
Cc: Anne van Kesteren <annevk@annevk.nl>, Jochen Eisinger <eisinger@google.com>, WebAppSec WG <public-webappsec@w3.org>
On Fri, May 1, 2015 at 10:39 AM, Mike West <mkwst@google.com> wrote:
> What inheritance cases beyond `about:blank` are you worried about?

The ones I'm not aware of right now... This about:blank case was one I
didn't think about while implementing it in Firefox, and I'm concerned
I missed something else.  But maybe it's prudent to address
about:blank in the spec (I think it's the majority of what was missed)
and circulate to see if we missed anything?

> I'll take a stab at rewriting the relevant bits of the spec in the vaguely
> near future: https://github.com/w3c/webappsec/issues/328.

Thanks!

-Sid
Received on Friday, 1 May 2015 16:48:04 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:12 UTC