On Fri, Sep 2, 2011 at 3:26 AM, Julian Reschke <[email protected]> wrote:
> On 2011-09-02 12:20, Adam Barth wrote:
>> I replied to Julian's message on a W3C list.  Julian, is there more
>> discussion you'd like to have about these points?
>> ...
>
> Well, as discussed, the syntax of the Origin header makes it hard to detect
> errors which happen when multiple instances get folded into one; see
> <http://greenbytes.de/tech/webdav/draft-ietf-httpbis-p2-semantics-latest.html#considerations.for.creating.header.fields>
> -- but I fear it's too late to fix this?

Unfortunately, yes.  Adding quotes would break the large number of
folks using already using this header.

Adam
_______________________________________________
websec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/websec

Reply via email to