20:59:56 RRSAgent has joined #webappsec 20:59:56 logging to http://www.w3.org/2013/08/27-webappsec-irc 21:00:22 Meeting: WebAppSec WG Teleconference, 27-August-2013 21:00:27 Chair: bhill2, ekr 21:00:46 Agenda: http://lists.w3.org/Archives/Public/public-webappsec/2013Aug/0056.html 21:00:49 ekr has joined #webappsec 21:01:00 zakim, who is here/ 21:01:00 I don't understand 'who is here/', ekr 21:01:05 zakim, who is here? 21:01:05 sorry, ekr, I don't know what conference this is 21:01:05 zakim, this is 92794 21:01:06 On IRC I see ekr, RRSAgent, Zakim, bhill2, gmaone, mkwst_, timeless, trackbot, odinho, tlr, wseltzer 21:01:06 ok, bhill2; that matches SEC_WASWG()5:00PM 21:01:12 +??P4 21:01:20 + +1.415.832.aaaa 21:01:22 zakim, who is here? 21:01:23 On the phone I see bhill2, [Mozilla], ??P4, +1.415.832.aaaa 21:01:24 On IRC I see ekr, RRSAgent, Zakim, bhill2, gmaone, mkwst_, timeless, trackbot, odinho, tlr, wseltzer 21:01:25 Zakim, ??P4 is gioma1 21:01:25 +gioma1; got it 21:01:30 zakim, ekr is at mozilla 21:01:30 I don't understand 'ekr is at mozilla', ekr 21:01:37 zakim, mozilla has ekr 21:01:37 +ekr; got it 21:01:39 Zakim, ??P4 is gmaone 21:01:39 I already had ??P4 as gioma1, gmaone 21:01:42 bhill2: thanks 21:01:46 -gioma1 21:01:59 zakim, aaaa is puhley 21:01:59 +puhley; got it 21:02:18 +??P4 21:02:24 Zakim, ??P4 is gmaone 21:02:24 +gmaone; got it 21:03:56 + +1.978.944.aabb 21:04:02 +mkwst_ 21:04:08 zakim, aabb is gopal 21:04:08 +gopal; got it 21:05:16 bhill2: I can scribe 21:05:30 scribenick ekr 21:05:32 scribenick: ekr 21:05:42 zakim, who is here? 21:05:42 On the phone I see bhill2, [Mozilla], puhley, gmaone, gopal, mkwst_ 21:05:43 [Mozilla] has ekr 21:05:44 On IRC I see ekr, RRSAgent, Zakim, bhill2, gmaone, mkwst_, timeless, trackbot, odinho, tlr, wseltzer 21:05:51 topic: Minutes Approval 21:05:55 http://www.w3.org/2013/07/16-webappsec-minutes.html 21:06:18 Topic: Tracker 21:06:18 https://www.w3.org/2011/webappsec/track/actions/open?sort=owner 21:06:29 https://www.w3.org/2011/webappsec/track/actions/pendingreview 21:06:56 puhley has joined #webappsec 21:07:35 trackbot close action-148 21:07:35 Closed action-148. 21:09:03 mwest: there has been a proposal that we add a much bigger API (#127). Don't know if we would get it done by 1.1 21:09:08 … we should discuss on the list 21:09:27 bhill2: would like to create a burndown list of outstanding issues 21:10:24 Topic: Closing CORS Open Isues 21:10:26 Topic: CORS CfC and open issues 21:10:41 https://www.w3.org/Bugs/Public/buglist.cgi?list_id=22771&query_format=advanced&bug_status=NEW&bug_status=ASSIGNED&bug_status=REOPENED&component=CORS&product=WebAppsSec 21:11:04 bhill2: do we intend to respond to any of these issues in the tracker? 21:11:17 bhill2: wanted to get consensus on the call. 21:11:24 … does anyone object to closing these out? 21:11:43 https://www.w3.org/Bugs/Public/show_bug.cgi?id=14663 : CORS and Caches 21:11:54 bhill2: I don't think there is a need for this at this point 21:12:01 any objections to closing this bug? 21:12:09 no objections 21:12:20 https://www.w3.org/Bugs/Public/show_bug.cgi?id=14664 : Defining CORS headers 21:12:35 bhill2: Not clear what the contents of this bug is. Open since 2011 with no activity 21:12:46 … might be about header changes in ABNF with HTTP bis 21:12:49 any objections to closing? 21:12:51 no objections 21:13:03 https://www.w3.org/Bugs/Public/show_bug.cgi?id=14700 : Point out that Access-Control-Allow-Origin:* is safe for servers not behind a firewall 21:13:12 bhill2: security considerations has been completely rewritten 21:13:16 any objections to closing? 21:13:21 no objections heard. 21:13:32 https://www.w3.org/Bugs/Public/show_bug.cgi?id=19920 : Don't allow space-separated origins in the syntax 21:13:49 Related to 21608: https://www.w3.org/Bugs/Public/show_bug.cgi?id=21608 7.2 "Resource Sharing Check" does not specify how to handle a space separated list in Access-Control-Allow-Origin 21:14:33 bhill2: implicitly access control sharing check forbids >1 oriign 21:14:43 … my opinion is behavior is already specified and implemented 21:14:53 … propose we don't change it 21:14:59 any objections to closing these without change? 21:15:06 no objections heard 21:15:37 https://www.w3.org/Bugs/Public/show_bug.cgi?id=21012 : Add more text on Vary 21:15:48 bhill2: seems that this is an edge case. 21:16:06 … minor editorial suggestion, not worth opening spec 21:16:12 any objections to closing these without change? 21:16:14 no objections heard 21:16:24 https://www.w3.org/Bugs/Public/show_bug.cgi?id=21013: Credentials and HTTP authentication 21:16:40 http://lists.w3.org/Archives/Public/public-webapps/2013JanMar/thread.html#msg366 21:16:44 bhill2: discussion more recently on the list. 21:17:17 … does anyone feel spec needs additional clarification? 21:17:28 … I have not seen any actual text proposed 21:17:45 any objections to closing this without changes? 21:17:47 no objections heard 21:18:14 bhill2: call to formally close CfC for advancement from Candidate Recommendation to Proposed Recommendation 21:19:03 peleus moves to advance CORS to PR 21:19:05 seconded by ekr 21:19:11 no objections to unanimous consent 21:19:22 decision: move CORS to proposed recommendation 21:19:35 bhill2: I will check with Art in WebApps 21:19:38 Topic: SOS proposal 21:19:40 http://lists.w3.org/Archives/Public/public-webappsec/2013Aug/0037.html 21:20:19 bhill2: proposed modiification to prevent against CSRF. Header to determne whether cookies would be sent or not 21:20:32 … a few items of discussion on the list 21:20:40 … anyone interested in taking this up? 21:20:55 nothing heard 21:21:00 bhill2: continue to discuss on the list 21:21:16 … but we will not take it up without more show of interest 21:21:19 in 1.1 21:21:34 -[Mozilla] 21:21:39 -gopal 21:21:42 -bhill2 21:21:43 -mkwst_ 21:21:43 rrsagent, generate minutes 21:21:43 I have made the request to generate http://www.w3.org/2013/08/27-webappsec-minutes.html ekr 21:21:43 -puhley 21:21:47 -gmaone 21:21:48 SEC_WASWG()5:00PM has ended 21:21:48 Attendees were bhill2, +1.415.832.aaaa, gioma1, ekr, puhley, gmaone, +1.978.944.aabb, mkwst_, gopal 21:21:50 thanks for scribing, ekr 21:21:55 np. 21:22:22 zakim, please part 21:22:22 Zakim has left #webappsec 21:22:28 rrsagent, draft minutes 21:22:28 I have made the request to generate http://www.w3.org/2013/08/27-webappsec-minutes.html ekr 21:22:32 rrsagent, please part 21:22:54 rrsagent, set logs world-visible 21:23:00 rrsagent, please part 21:23:00 I see no action items