<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>19746</bug_id>
          
          <creation_ts>2012-10-28 17:04:34 +0000</creation_ts>
          <short_desc>IETF issues</short_desc>
          <delta_ts>2019-03-30 19:47:36 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WHATWG</product>
          <component>MIME</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>MOVED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P1</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>Unsorted</target_milestone>
          <dependson>19865</dependson>
    
    <dependson>19866</dependson>
    
    <dependson>19989</dependson>
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Larry Masinter">lmm</reporter>
          <assigned_to name="Gordon P. Hemsley">gphemsley</assigned_to>
          <cc>annevk</cc>
    
    <cc>lmm</cc>
    
    <cc>mike</cc>
    
    <cc>Nasserbufahad</cc>
    
    <cc>w3c</cc>
          
          <qa_contact>sideshowbarker+mimespec</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>77213</commentid>
    <comment_count>0</comment_count>
    <who name="Larry Masinter">lmm</who>
    <bug_when>2012-10-28 17:04:34 +0000</bug_when>
    <thetext>http://trac.tools.ietf.org/wg/websec/trac/query?component=mime-sniff

and http://tools.ietf.org/wg/websec/minutes?item=minutes82.html
http://tools.ietf.org/agenda/82/slides/websec-2.pdf</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>77664</commentid>
    <comment_count>1</comment_count>
    <who name="Gordon P. Hemsley">gphemsley</who>
    <bug_when>2012-11-01 14:40:17 +0000</bug_when>
    <thetext>(In reply to comment #0)
&gt; http://trac.tools.ietf.org/wg/websec/trac/query?component=mime-sniff
&gt; 
&gt; http://tools.ietf.org/agenda/82/slides/websec-2.pdf

I&apos;ll get to these after I complete the rewrite.

&gt; and http://tools.ietf.org/wg/websec/minutes?item=minutes82.html

Is there any actionable information here?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>77697</commentid>
    <comment_count>2</comment_count>
    <who name="Gordon P. Hemsley">gphemsley</who>
    <bug_when>2012-11-01 20:11:19 +0000</bug_when>
    <thetext>(In reply to comment #1)
&gt; (In reply to comment #0)
&gt; &gt; http://trac.tools.ietf.org/wg/websec/trac/query?component=mime-sniff
&gt; &gt; 
&gt; &gt; http://tools.ietf.org/agenda/82/slides/websec-2.pdf
&gt; 
&gt; I&apos;ll get to these after I complete the rewrite.

To expedite this process, it would be helpful if the issues that remain relevant after the rewrite are filed individually here in this Bugzilla component and marked as blocking this bug. Many of them were filed over a year ago, and it&apos;s not clear how (or whether) they relate to the current state of the document.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>77893</commentid>
    <comment_count>3</comment_count>
    <who name="Larry Masinter">lmm</who>
    <bug_when>2012-11-05 17:31:55 +0000</bug_when>
    <thetext>Based on a quick review on 11/5/2012 I think most all of the comments raised are still relevant. 

FTP and file systems do not supply content-types, and sniffing uses file extensions.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>77901</commentid>
    <comment_count>4</comment_count>
    <who name="Gordon P. Hemsley">gphemsley</who>
    <bug_when>2012-11-05 19:00:35 +0000</bug_when>
    <thetext>(In reply to comment #3)
&gt; Based on a quick review on 11/5/2012 I think most all of the comments raised
&gt; are still relevant. 

A lot of them seem rather speculative to me, so I&apos;d appreciate it if they were refiled here with more detailed descriptions about what the issue is and what current behavior is.

&gt; FTP and file systems do not supply content-types, and sniffing uses file
&gt; extensions.

As currently written, the spec does not describe how media type is determined by the file system or protocols that are not HTTP. That behavior is left undefined or defined by other documents.

A previous draft of the spec went so far as to say that no file sniffing should be done at all for protocols such as FTP.

The spec also makes clear that file extensions are not to be used for resources retrieved via HTTP.

I&apos;m not really sure what behavior you&apos;re desiring here for non-HTTP resources.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78431</commentid>
    <comment_count>5</comment_count>
    <who name="Gordon P. Hemsley">gphemsley</who>
    <bug_when>2012-11-17 05:35:06 +0000</bug_when>
    <thetext>I fixed Ticket #20:

https://github.com/whatwg/mimesniff/commit/75c2afdefe39b01a00f133a4125d58bd46f88d79</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78432</commentid>
    <comment_count>6</comment_count>
    <who name="Gordon P. Hemsley">gphemsley</who>
    <bug_when>2012-11-17 05:55:36 +0000</bug_when>
    <thetext>Regarding Ticket #21:

XML types are already assumed to be tagged correctly. Sniffing XML types is very limited.

However, other polyglot types are not handled properly at this point. ZIP is probably the most egregious, since ZIP-based types will all explicitly be sniffed as ZIP; perhaps ZIP should be handled similarly to XML. Examples such as TIFF vs. DNG are not mentioned at all, so their sniffing is undefined.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>78434</commentid>
    <comment_count>7</comment_count>
    <who name="Gordon P. Hemsley">gphemsley</who>
    <bug_when>2012-11-17 06:20:17 +0000</bug_when>
    <thetext>Filed bug 19989 for the ZIP issue.

The following IETF websec issues are either handled by the current draft of the mimesniff document or are wontfix: #15, #17, #18, #19, #16.

Please mark them as appropriate in the websec tracker and file any related outstanding concerns here in Bugzilla.

Please also make note in the respective websec tracker issues of the bugs on file here on Bugzilla for some of the remaining issues, and of the issues that have already been fixed.

I await Hixie and Anne&apos;s thoughts regarding issue #22.

Also, it is not clear to me what to do with issue #24; I&apos;m not sure how related the mimesniff spec is to Widget Packaging and XML Configuration at this point.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>83929</commentid>
    <comment_count>8</comment_count>
    <who name="Marcos Caceres">w3c</who>
    <bug_when>2013-03-04 10:16:27 +0000</bug_when>
    <thetext>Regarding #24, you can probably ignore that. There have not been any interoperability issues reported ... so, if it ain&apos;t broke, you know...  

However, the app:// URI scheme does rely heavily on this specification to work out the content type of things inside zip packages:

http://appuri.sysapps.org/

We should make sure the specs stay aligned.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>129727</commentid>
    <comment_count>9</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2019-03-30 19:47:36 +0000</bug_when>
    <thetext>https://github.com/whatwg/mimesniff/issues/99</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>