RE: webappsec tests moved to GitHub

2013-06-13 Thread HU, BIN
Odin, Great job. I am working on testing documentation stuff. One of the document is the Migration Process for WG's to move to Github. Since you have done the migration, do you have any experience and thoughts to share so that we can well document it and make the migration job of other WGs

RE: Fetch: HTTP authentication and CORS

2013-05-08 Thread HU, BIN
That is correct. Thanks Bin From: Paul Libbrecht [mailto:p...@hoplahup.net] Sent: Wednesday, May 08, 2013 1:14 PM To: HU, BIN Cc: Hallvord Reiar Michaelsen Steen; Jonas Sicking; Anne van Kesteren; WebApps WG; WebAppSec WG Subject: Re: Fetch: HTTP authentication and CORS On 7 mai 2013, at 02:23

RE: Re: Fetch: HTTP authentication and CORS

2013-05-06 Thread HU, BIN
If we are talking about RFC2617 HTTP Authentication, there are 2 authentication models: (1) Basic Authentication model: Under this circumstance, basically client can send the username:password pair at the first request, e.g. in the form: https://username:passw...@www.example.com/path which

RE: [XHR] test nitpicks: MIME type / charset requirements

2013-05-06 Thread HU, BIN
Since XHR is the API to facilitate a valid HTTP transaction, IMHO, it should be fully compliant with HTTP - no more and no less. A valid HTTP request and response should be interpreted consistently across UA's and devices. Interoperability is very important across UA's and devices. If the XHR,

RE: Reminder: Please register for Face to face by Friday

2013-04-03 Thread HU, BIN
Paypal was acquired by eBay, but kept Paypal brand, called eBay's Paypal business. Bin Hu | Service Standards | ATT +1-425-214-3305 From: Chris Wilson [mailto:cwi...@google.com] Sent: Wednesday, April 03, 2013 3:15 PM To: Travis Leithead Cc: Chaals Nevile; public-webapps WG Subject: Re: