"Uniform Messaging, a CSRF resistant profile of CORS"

FYI, re ACTION-331, tracking the confused deputy issue in CORS work


I haven't looked at the proposal closely, so I can't vouch
for the claim in the subject/title.

