<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>13229</bug_id>
          
          <creation_ts>2011-07-13 00:09:44 +0000</creation_ts>
          <short_desc>The following text from the &quot;Security considerations&quot; part of &quot;11 IANA considerations&quot; is wrong: &quot;An event stream from an origin distinct from the origin of the content consuming the event stream can result in information leakage. To avoid this, user agen</short_desc>
          <delta_ts>2011-08-04 22:02:58 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebAppsWG</product>
          <component>HISTORICAL - Server-Sent Events (editor: Ian Hickson)</component>
          <version>unspecified</version>
          <rep_platform>Other</rep_platform>
          <op_sys>other</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WORKSFORME</resolution>
          
          
          <bug_file_loc>http://www.whatwg.org/specs/web-apps/current-work/#top</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>contributor</reporter>
          <assigned_to name="Ian &apos;Hixie&apos; Hickson">ian</assigned_to>
          <cc>ian</cc>
    
    <cc>mike</cc>
    
    <cc>public-webapps</cc>
          
          <qa_contact>public-webapps-bugzilla</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>50955</commentid>
    <comment_count>0</comment_count>
    <who name="">contributor</who>
    <bug_when>2011-07-13 00:09:44 +0000</bug_when>
    <thetext>Specification: http://dev.w3.org/html5/eventsource/
Multipage: http://www.whatwg.org/C#top
Complete: http://www.whatwg.org/c#top

Comment:
The following text from the &quot;Security considerations&quot; part of &quot;11 IANA
considerations&quot; is wrong:

&quot;An event stream from an origin distinct from the origin of the content
consuming the event stream can result in information leakage. To avoid this,
user agents are required to block all cross-origin loads.&quot;

Posted from: 2620:101:8003:200:226:bbff:fe05:3fe1
User agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:8.0a1) Gecko/20110707 Firefox/8.0a1 Firefox/8.0a1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>54205</commentid>
    <comment_count>1</comment_count>
    <who name="Ian &apos;Hixie&apos; Hickson">ian</who>
    <bug_when>2011-08-04 22:02:58 +0000</bug_when>
    <thetext>already fixed</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>