<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>17802</bug_id>
          
          <creation_ts>2012-07-18 04:37:52 +0000</creation_ts>
          <short_desc>appcache: SOP requirement for cache manifest files should be relaxed (at least) by CORS.</short_desc>
          <delta_ts>2012-07-23 03:55:10 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WHATWG</product>
          <component>HTML</component>
          <version>unspecified</version>
          <rep_platform>Other</rep_platform>
          <op_sys>other</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WONTFIX</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>Unsorted</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>contributor</reporter>
          <assigned_to name="Ian &apos;Hixie&apos; Hickson">ian</assigned_to>
          <cc>adrianba</cc>
    
    <cc>annevk</cc>
    
    <cc>blizzard</cc>
    
    <cc>ian</cc>
    
    <cc>jonas</cc>
    
    <cc>michaeln</cc>
    
    <cc>mike</cc>
    
    <cc>tobie.langel</cc>
          
          <qa_contact>contributor</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>70072</commentid>
    <comment_count>0</comment_count>
    <who name="">contributor</who>
    <bug_when>2012-07-18 04:37:52 +0000</bug_when>
    <thetext>This was was cloned from bug 14705 as part of operation convergence.
Originally filed: 2011-11-05 21:49:00 +0000
Original reporter: Tobie Langel &lt;tobie.langel@gmail.com&gt;

================================================================================
 #0   Tobie Langel                                    2011-11-05 21:49:20 +0000 
--------------------------------------------------------------------------------
This enables putting the manifest files on a CDN.
================================================================================
 #1   Ian &apos;Hixie&apos; Hickson                             2011-11-11 00:22:15 +0000 
--------------------------------------------------------------------------------
Status: Rejected
Change Description: no spec change
Rationale: It would also enable a hostile open wifi access point to permanently hijack facebook.com to point to evil.example.net, which seems, to put it mildly, problematic.
================================================================================
 #2   michaeln@google.com                             2011-11-11 20:44:58 +0000 
--------------------------------------------------------------------------------
Reopening in the hopes of gathering more input about why the SOP for this is a problem and what might be done to resolve it.
================================================================================
 #3   Ian &apos;Hixie&apos; Hickson                             2011-12-03 22:23:56 +0000 
--------------------------------------------------------------------------------
Reassigning to michaeln as per comment 2. If you gather actionable input, please don&apos;t hesitate to reassign this to me so I can study it further.
================================================================================
 #4   Tobie Langel                                    2012-01-24 22:14:21 +0000 
--------------------------------------------------------------------------------
This was an attempt at solving use-case #2 here: http://www.w3.org/community/fixing-appcache/2012/01/18/appcache_use_cases/#use_case_2

Allow an application hosted on a cluster of servers to be easily updated
An application is hosted on a cluster of servers behind a non-sticky load balancer. It is updated daily. Even though all servers are not updated instantly and two versions of the application co-exist for a while, it is possible to update the application without risking to have an out-of sync version of the application (e.g. manifest file and assets of the latest version combined with a Master Entry of the previous version) or to need to invalidate the cache to avoid such issues.

Probably would have been more useful to provide the use case upfront rather that potential solutions.
================================================================================</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>71242</commentid>
    <comment_count>1</comment_count>
    <who name="Ian &apos;Hixie&apos; Hickson">ian</who>
    <bug_when>2012-07-20 04:32:44 +0000</bug_when>
    <thetext>I can&apos;t see how to do this safely. I recommend just having all the backend servers have the same publicly-visible host name with load balancing.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>