W3C

Edit comment LC-2267 for Mobile Web Best Practices Working Group

Quick access to

Previous: LC-2268

Comment LC-2267
:
Commenter: Thomas Roessler <tlr@w3.org>

or
Resolution status:

From a quick review, section 4.2.9.3 looks vastly improved. I'll
solicit the WSC WG's opinions on the changed version; speaking
personally, I'm happy with the current text.

I would like to call out a specific point in 4.2.9.2:

> Proxies must preserve security between requests for domains that are
> not same-origin in respect of cookies and scripts.

It is probably worthwhile to call out in non-normative security
considerations what that actually means -- namely, fairly heavy
rewriting of scripts along the lines of what CaJa does, and rewriting
of cookies to emulate the behavior that a browser would otherwise show.
(space separated ids)
(Please make sure the resolution is adapted for public consumption)


Developed and maintained by Dominique Hazaël-Massieux (dom@w3.org).
$Id: 2267.html,v 1.1 2017/08/11 06:43:23 dom Exp $
Please send bug reports and request for enhancements to w3t-sys.org