<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>7599</bug_id>
          
          <creation_ts>2009-09-13 11:24:20 +0000</creation_ts>
          <short_desc>Either drop the two places that set the &quot;Origin&quot; HTTP header, or update HTML5 to match the Sec-From/Origin I-D (if the latter is stable enough yet).</short_desc>
          <delta_ts>2010-10-04 14:55:14 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>HTML WG</product>
          <component>pre-LC1 HTML5 spec (editor: Ian Hickson)</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>VERIFIED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://www.whatwg.org/specs/web-apps/current-work/#navigate-fragid-step</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>NE, NoReply</keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>LC</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>contributor</reporter>
          <assigned_to name="Ian &apos;Hixie&apos; Hickson">ian</assigned_to>
          <cc>julian.reschke</cc>
    
    <cc>mike</cc>
    
    <cc>public-html-admin</cc>
    
    <cc>public-html-wg-issue-tracking</cc>
    
    <cc>w3c</cc>
          
          <qa_contact name="HTML WG Bugzilla archive list">public-html-bugzilla</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>27118</commentid>
    <comment_count>0</comment_count>
    <who name="">contributor</who>
    <bug_when>2009-09-13 11:24:20 +0000</bug_when>
    <thetext>Section: http://www.whatwg.org/specs/web-apps/current-work/#navigate-fragid-step

Comment:
Either drop the two places that set the &quot;Origin&quot; HTTP header, or update HTML5 to match the Sec-From/Origin I-D (if the latter is stable enough yet).

Posted from: 98.248.33.53</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>27478</commentid>
    <comment_count>1</comment_count>
    <who name="Adam Barth">w3c</who>
    <bug_when>2009-09-22 05:53:59 +0000</bug_when>
    <thetext>It would be helpful to rename Origin to Sec-From and to incorporate the list of privacy-sensitive contexts from this page:

https://wiki.mozilla.org/Security/Sec-From</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>27655</commentid>
    <comment_count>2</comment_count>
    <who name="Adam Barth">w3c</who>
    <bug_when>2009-09-24 23:31:38 +0000</bug_when>
    <thetext>We&apos;ve harmonized the Origin header with CORS.  There is no need to renamed the header anymore, but it would be useful to list the privacy-sensitive contexts as described in Comment #1.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>27739</commentid>
    <comment_count>3</comment_count>
    <who name="">contributor</who>
    <bug_when>2009-09-28 23:43:37 +0000</bug_when>
    <thetext>Checked in as WHATWG revision r4011.
Check-in comment: Synchronise with the latest Origin spec rules and semantics.
http://html5.org/tools/web-apps-tracker?from=4010&amp;to=4011
</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>33438</commentid>
    <comment_count>4</comment_count>
    <who name="Maciej Stachowiak">mjs</who>
    <bug_when>2010-03-14 14:51:07 +0000</bug_when>
    <thetext>This bug predates the HTML Working Group Decision Policy.

If you are satisfied with the resolution of this bug, please change the state of this bug to CLOSED. If you have additional information and would like the editor to reconsider, please reopen this bug. If you would like to escalate the issue to the full HTML Working Group, please add the TrackerRequest keyword to this bug, and suggest title and text for the tracker issue; or you may create a tracker issue yourself, if you are able to do so. For more details, see this document:
  http://dev.w3.org/html5/decision-policy/decision-policy.html

This bug is now being moved to VERIFIED. Please respond within two weeks. If this bug is not closed, reopened or escalated within two weeks, it may be marked as NoReply and will no longer be considered a pending comment.
</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>