On 5/15/06, Jim Ley <[EMAIL PROTECTED]> wrote:
I don't agree on a "whitelist" that everyone can agree on supporting, since
if we put CHICKENS on a whitelist and a UA decides that is actually insecure
and blocks it, it should be free to do so, so the whitelist will give us
nothing, simply SHOULD support any VERB, and you're free to block any you
want for security reasons is a much more sensible policy than a non
mandatory whitelist.

+1 for "SHOULD support any VERB" with specific notations about
currently blacklisted verbs.

--
Brad Fults
NeatBox

Reply via email to