/lists.whatwg.org/pipermail/whatwg-whatwg.org/2008-September/016358.html

https://github.com/whatwg/whatwg.org · HTML · 72 lines · 60 code · 5 blank · 7 comment · 0 complexity · 6989925330d82dd76a38d21a7e734963 MD5 · raw file

  1. <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
  2. <HTML>
  3. <HEAD>
  4. <TITLE> [whatwg] WebSocket websocket-origin
  5. </TITLE>
  6. <LINK REL="Index" HREF="index.html" >
  7. <LINK REL="made" HREF="mailto:whatwg%40lists.whatwg.org?Subject=Re%3A%20%5Bwhatwg%5D%20WebSocket%20websocket-origin&In-Reply-To=%3Cop.uh8969an64w2qv%40annevk-t60.oslo.opera.com%3E">
  8. <META NAME="robots" CONTENT="index,nofollow">
  9. <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
  10. <LINK REL="Previous" HREF="016343.html">
  11. <LINK REL="Next" HREF="016377.html">
  12. </HEAD>
  13. <BODY BGCOLOR="#ffffff">
  14. <H1>[whatwg] WebSocket websocket-origin</H1>
  15. <!--htdig_noindex-->
  16. <B>Anne van Kesteren</B>
  17. <A HREF="mailto:whatwg%40lists.whatwg.org?Subject=Re%3A%20%5Bwhatwg%5D%20WebSocket%20websocket-origin&In-Reply-To=%3Cop.uh8969an64w2qv%40annevk-t60.oslo.opera.com%3E"
  18. TITLE="[whatwg] WebSocket websocket-origin">annevk at opera.com
  19. </A><BR>
  20. <I>Mon Sep 29 11:41:23 PDT 2008</I>
  21. <P><UL>
  22. <LI>Previous message: <A HREF="016343.html">[whatwg] Dealing with UI redress vulnerabilities inherent to the current web
  23. </A></li>
  24. <LI>Next message: <A HREF="016377.html">[whatwg] WebSocket websocket-origin
  25. </A></li>
  26. <LI> <B>Messages sorted by:</B>
  27. <a href="date.html#16358">[ date ]</a>
  28. <a href="thread.html#16358">[ thread ]</a>
  29. <a href="subject.html#16358">[ subject ]</a>
  30. <a href="author.html#16358">[ author ]</a>
  31. </LI>
  32. </UL>
  33. <HR>
  34. <!--/htdig_noindex-->
  35. <!--beginarticle-->
  36. <PRE>What is the reason for doing literal comparison on the websocket-origin
  37. and websocket-location HTTP headers? Access Control for Cross-Site
  38. Requests is currently following this design for
  39. access-control-allow-origin but sicking is complaining about so maybe it
  40. should be URL-without-&lt;path&gt; comparison instead. (E.g., then
  41. <A HREF="http://example.org">http://example.org</A> and <A HREF="http://example.org:80">http://example.org:80</A> would be equivalent.)
  42. --
  43. Anne van Kesteren
  44. &lt;<A HREF="http://annevankesteren.nl/">http://annevankesteren.nl/</A>&gt;
  45. &lt;<A HREF="http://www.opera.com/">http://www.opera.com/</A>&gt;
  46. </PRE>
  47. <!--endarticle-->
  48. <!--htdig_noindex-->
  49. <HR>
  50. <P><UL>
  51. <!--threads-->
  52. <LI>Previous message: <A HREF="016343.html">[whatwg] Dealing with UI redress vulnerabilities inherent to the current web
  53. </A></li>
  54. <LI>Next message: <A HREF="016377.html">[whatwg] WebSocket websocket-origin
  55. </A></li>
  56. <LI> <B>Messages sorted by:</B>
  57. <a href="date.html#16358">[ date ]</a>
  58. <a href="thread.html#16358">[ thread ]</a>
  59. <a href="subject.html#16358">[ subject ]</a>
  60. <a href="author.html#16358">[ author ]</a>
  61. </LI>
  62. </UL>
  63. <hr>
  64. <a href="http://lists.whatwg.org/listinfo.cgi/whatwg-whatwg.org">More information about the whatwg
  65. mailing list</a><br>
  66. <!--/htdig_noindex-->
  67. </body></html>