<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>23706</bug_id>
          
          <creation_ts>2013-11-01 17:16:47 +0000</creation_ts>
          <short_desc>authentication entry scope</short_desc>
          <delta_ts>2014-11-03 10:50:14 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WHATWG</product>
          <component>Fetch</component>
          <version>unspecified</version>
          <rep_platform>PC</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard>blocked on insufficient interest</status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>Unsorted</target_milestone>
          
          <blocked>26556</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="Anne">annevk</reporter>
          <assigned_to name="Anne">annevk</assigned_to>
          <cc>mike</cc>
          
          <qa_contact>sideshowbarker+fetchspec</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>95694</commentid>
    <comment_count>0</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2013-11-01 17:16:47 +0000</bug_when>
    <thetext>We need to be clearer about the persistence of this. E.g. tie it to some kind of session concept. And maybe document risks and learned lessons at some point.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>95819</commentid>
    <comment_count>1</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2013-11-05 17:57:16 +0000</bug_when>
    <thetext>I guess saying the user agent can cache it for this URL is good enough. Session concept seems to be something user agent specific that has not made its way into specifications yet. (See e.g. HSTS for something else that just ties it to the user agent.)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106563</commentid>
    <comment_count>2</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2014-05-21 13:45:34 +0000</bug_when>
    <thetext>http://tools.ietf.org/html/draft-ietf-httpbis-p7-auth-26#section-2.2 seems clear enough...</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>114426</commentid>
    <comment_count>3</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2014-11-03 10:50:14 +0000</bug_when>
    <thetext>https://github.com/whatwg/fetch/commit/bffaa17cdad4f7924548233d24ff14b0ae793bbb</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>