On Thu, 22 Nov 2007 19:33:27 +0100, Bjoern Hoehrmann <[EMAIL PROTECTED]> wrote:
It seems the current draft does not discuss HttpOnly cookies and other
headers that implementations may not want to expose. Can we have a Se-
curity Considerations section that clarifies that implementations may,
at their discretion, not expose certain headers, perhaps giving Http-
Only cookies as an example where that may be desired? I would expect any
future HttpOnly cookie specification to discuss its relationship with
XmlHTTPRequest in more detail, so I don't think we should include more
of it than citing it as example.

I added this:

  http://dev.w3.org/2006/webapi/XMLHttpRequest/#security


--
Anne van Kesteren
<http://annevankesteren.nl/>
<http://www.opera.com/>

Reply via email to