Re: HTTPOnly cookies specification

2009-01-06 Thread Bil Corry
Bil Corry wrote on 12/16/2008 6:55 PM: > One option I'm considering is doing as you suggest, writing an entire > cookie spec as it exists now, then add the features to cookies > necessary to provide integrity and privacy. I spoke with Ian > Hickson, he said IETF is the proper place for this work,

Re: HTTPOnly cookies specification

2008-12-16 Thread Bil Corry
Jonas Sicking wrote on 12/16/2008 6:05 PM: > Out of curiosity, what do you want to specify beyond what XMLHttpRequest > and HTML5 specifies? HTML5 only contains a disclaimer: - This specification does not define what makes an HTTP-only cookie, and at the time of publication the editor is no

Re: HTTPOnly cookies specification

2008-12-16 Thread Jonas Sicking
Bil Corry wrote: Jonas Sicking wrote on 12/16/2008 4:32 PM: Bil Corry wrote: There's a group of us working on creating a spec for HTTPOnly cookies. We have a draft of the HTTPOnly scope available to review: http://docs.google.com/View?docid=dxxqgkd_0cvcqhsdw If you have an active interes

Re: HTTPOnly cookies specification

2008-12-16 Thread Bil Corry
Jonas Sicking wrote on 12/16/2008 4:32 PM: > Bil Corry wrote: >> There's a group of us working on creating a spec for HTTPOnly >> cookies. We have a draft of the HTTPOnly scope available to review: >> >> http://docs.google.com/View?docid=dxxqgkd_0cvcqhsdw >> >> If you have an active interest

Re: HTTPOnly cookies specification

2008-12-16 Thread Jonas Sicking
Bil Corry wrote: There's a group of us working on creating a spec for HTTPOnly cookies. We have a draft of the HTTPOnly scope available to review: http://docs.google.com/View?docid=dxxqgkd_0cvcqhsdw If you have an active interest in participating, our list is here: http://gro

Re: HTTPOnly cookies specification

2008-12-12 Thread Bil Corry
Stefanos Harhalakis wrote on 12/12/2008 1:49 PM: > My personal opinion is that any IETF related conversation regarding this > issue > should happen at ietf-http-wg list (unless a new WG is created). As you point out, I did post to ietf-http-wg and the feedback I received was that someone shoul

Re: HTTPOnly cookies specification

2008-12-12 Thread Stefanos Harhalakis
l#a16117176 http://www.nabble.com/HTTPOnly-Cookies-Specification-to20611621.html#a20611621 My personal opinion is that any IETF related conversation regarding this issue should happen at ietf-http-wg list (unless a new WG is created). Otherway it should be moved to the general purpose apps-discu

Re: HTTPOnly cookies specification

2008-12-12 Thread Bil Corry
Gervase Markham wrote on 12/12/2008 11:23 AM: > Bil Corry wrote: >> There's a group of us working on creating a spec for HTTPOnly cookies. > > This isn't being done by WHAT-WG, then? > >> If you have an active interest in participating, our list is here: >> >> http://groups.google.com/grou

Re: HTTPOnly cookies specification

2008-12-12 Thread Gervase Markham
Bil Corry wrote: > There's a group of us working on creating a spec for HTTPOnly cookies. This isn't being done by WHAT-WG, then? > If you have an active interest in participating, our list is here: > > http://groups.google.com/group/ietf-httponly-wg Is this an official IETF group? It se

HTTPOnly cookies specification

2008-12-12 Thread Bil Corry
There's a group of us working on creating a spec for HTTPOnly cookies. We have a draft of the HTTPOnly scope available to review: http://docs.google.com/View?docid=dxxqgkd_0cvcqhsdw If you have an active interest in participating, our list is here: http://groups.google.com/grou