Tobias,

 I'm happy to move the discussion primarily to websec, and I'll drop the cc: to 
webappsec after this email.  Thanks for the historical clarification, as well.

I'm not terribly concerned about which group does the work, as much as arriving 
at the engineering solution that works best for user agent and resource 
authors, some of whom have expressed preference for moving this functionality 
into CSP.  As both a chair and an individual, I don't have a strong preference, 
but I think there are reasons in favor of each option and it is worth 
re-opening the discussion now that the WebAppSec WG has a concrete deliverable 
under development to address the same general class of attacks.

I'll send out a summary shortly of the similarities and differences between the 
various options currently proposed for some additional context.

-Brad Hill




_______________________________________________
websec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/websec

Reply via email to