ISSUE-123: Safe Form Bar: HTTP assumptions in "no TLS" section [Techniques]

ISSUE-123: Safe Form Bar: HTTP assumptions in "no TLS" section [Techniques]

http://www.w3.org/2006/WSC/track/issues/

Raised by: Thomas Roessler
On product: Techniques

The current text assumes that there is always a meaningful interaction that can be described as "see if there's a secure version of this."  The text seems to assume that the form the editor bar is dealing with was retrieved by way of a GET request; in this event, the assumption probably (but not always) holds.

In case of POST, the assumption most of the time *won't* hold.

See also RFC 2616, safe vs unsafe.

Received on Thursday, 11 October 2007 10:21:16 UTC