Newsgroups: mozilla.dev.security
From: Jonas Sicking <jo...@sicking.cc>
Date: Tue, 16 Dec 2008 16:05:19 -0800
Local: Tues, Dec 16 2008 7:05 pm
Subject: Re: HTTPOnly cookies specification
Bil Corry wrote: Out of curiosity, what do you want to specify beyond what XMLHttpRequest > Jonas Sicking wrote on 12/16/2008 4:32 PM: >> Bil Corry wrote: >>> There's a group of us working on creating a spec for HTTPOnly >>> cookies. We have a draft of the HTTPOnly scope available to review: >>> http://docs.google.com/View?docid=dxxqgkd_0cvcqhsdw >>> If you have an active interest in participating, our list is here: >>> http://groups.google.com/group/ietf-httponly-wg > That's what Dan Winship said (more or less): > http://lists.w3.org/Archives/Public/ietf-http-wg/2008OctDec/0235.html > I do agree that cookies could use a massive overhaul, taking the original Netscape cookie spec, RFCs 2109, 2964, and 2965, along with Yngve Pettersen's 2965 replacement draft and merge them all together with the real-world implementations (HTTPOnly, etc) and from that, create one spec to rule them all. > But as I replied to Stefanos; Mozilla, WebKit and Microsoft have all recently updated their HTTPOnly features -- we want to piggyback on that momentum to get HTTPOnly implemented in a standard way without having to wait another year or two for a comprehensive cookie overhaul. and HTML5 specifies? / Jonas You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||