From nobody Sun Jul 2 00:54:19 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -7.682 X-Spam-Level: X-Spam-Status: No, score=-7.682 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 02 Jul 2017 00:54:15 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1498982055; bh=5SVx7WE77pHjBx9Pf7j4K42sKaCKAYSHrm6rD9s16EE=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=rkZLeo+MGdsMqekx4iCfQ+q8W6TEjuMQS/JK2JVpykwGj/1wsX5Mb0bYs3rQdoqpI HLcN1Slq4eFLC7HtefrP9JI+tTK4vhM1ucvx1P94efgmOkEUzjKY6NX2ZgORcdX8Vh ksYmFVlTOJyS87MBP7m6BCGzVTFViI1C0nlmJRlE= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Address client-hints-04 feedback (#361) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_5958a6a7ddcb4_26aa3fa1893fdc38124021"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 02 Jul 2017 07:54:19 -0000 ----==_mimepart_5958a6a7ddcb4_26aa3fa1893fdc38124021 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @reschke can you take another pass, please? Want to make sure we caught all of your feedback here. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/361#issuecomment-312476698 ----==_mimepart_5958a6a7ddcb4_26aa3fa1893fdc38124021 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@reschke can you take another pass, please? Want to make sure we caught all of your feedback here.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_5958a6a7ddcb4_26aa3fa1893fdc38124021-- From nobody Sun Jul 2 15:42:00 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -2.021 X-Spam-Level: X-Spam-Status: No, score=-2.021 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=s5UJDT9w9Xp2WcVL/NNvsvrXj5Y=; b=LEyc8gZ+4AN5MEoU XmDzEfXpcZW7IqFPUmbcprE4QpX+zR9oqZr/lK4PRHoLDJrtodMUIugKeNq2ItS2 ghqfz/iBb3lgJuL3FZJelyyF8CFGdcxyJ3ImfOAO7OpdJU3ie1Nc4bfGfSWtUZnE e06WK0gW5nGz+aYFerZPvQZCuaw= Date: Sun, 02 Jul 2017 22:41:56 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Geolocation Header (#364) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595976b3d5565_66a13fac91c55c384718"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 02 Jul 2017 22:41:59 -0000 ----==_mimepart_595976b3d5565_66a13fac91c55c384718 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable @mnot I suggested to @luisbargu that we should start a thread here first to= hash out a few high-level questions about the existing proposal and possib= le CH integration, before we take it to the wider list. I'll re-open this, = but if you feel that this belongs on the list, we can take it there. --- First off, I think CH is a great conceptual fit to what @luisbargu is propo= sing, and I'd _really_ love to see us reusing established CH mechanism to e= ase implementation, both on the UA/client side and for developers =E2=80=94= this makes everyone's life easier. I'll leave the "what" discussion, like = granularity and type of data delivered via this hint, for a separate discus= sion, and focus on the how here... >Header sent from the server to the user agent when a host is compatible wi= th the Geolocation > Header and is requesting geolocation to be attached in subsequent request= s. > >>Geolocation-Request: Path=3D"/localService"; Type=3DIfAlreadyGranted; Exp= ires=3DThu, 18 Dec 2017 12:00:00 UTC The CH mechanism for the above is: > Accept-CH: Geolocation > Accept-CH-Lifetime: 86400 (seconds) There are two bits missing: Path and Type.=20 ### Path This is something we considered for CH in the past =E2=80=94 "I want to sco= pe my hints to a subpath" =E2=80=94 but punted on due to limited (or so we = deemed at the time, at least) utility vs implementation complexity tradeoff= (equivalent to cookie paths, which is a burden we didn't want to take on).= In the last few years of CH experiments, I've not heard any complaints or = requests for this. I think that was the right call, and I'd suggest we stic= k with it. ### Type fwiw, I'd like to make an argument that we should omit this. The idea here = is to enable sites to trigger a permission prompt via a header, which seems= convenient on the surface, but experience shows that this is a bad UX patt= ern: you [should be using JS API to trigger permission prompt after explain= ing the intent](https://docs.google.com/document/d/1WNPIS_2F0eyDm5SS2E6LZ_7= 5tk6XtBSnR1xNjWJ_DPE/edit) and motivation. The incremental value we're addi= ng with the header trigger is low, and seems more like a footgun.=20 If you buy both of the above, then CH has all the necessary building blocks= to enable Geolocation.=20 --- @luisbargu WDYT? How critical, or not, are Path and Type for the use case y= ou had in mind? @yoavweiss curious to hear your thoughts on the above, and Geolocation use = case for CDNs. @mnot tactical question: what's the right process for followup RFC's to "re= gister" hints to be compatible with Accept-CH? Do we need any extra steps i= n CH for a registry, or some extension hooks? --=20 You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/364#issuecomment-312521490= ----==_mimepart_595976b3d5565_66a13fac91c55c384718 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

@mnot I s= uggested to @luisbargu that we should start a thread here first to hash out a few = high-level questions about the existing proposal and possible CH integratio= n, before we take it to the wider list. I'll re-open this, but if you feel = that this belongs on the list, we can take it there.


First off, I think CH is a great conceptual fit to what @luisbargu is proposing= , and I'd really love to see us reusing established CH mechanism t= o ease implementation, both on the UA/client side and for developers =E2=80= =94 this makes everyone's life easier. I'll leave the "what" discussion, li= ke granularity and type of data delivered via this hint, for a separate dis= cussion, and focus on the how here...

Header sent from the server to the user agent when a host is compatible = with the Geolocation
Header and is requesting geolocation to be attached in subsequent requests.=

Geolocation-Request: Path=3D"/localService"; Type=3DIfAlreadyGranted; Ex= pires=3DThu, 18 Dec 2017 12:00:00 UTC

The CH mechanism for the above is:

Accept-CH: Geolocation
Accept-CH-Lifetime: 86400 (seconds)

There are two bits missing: Path and Type.

Path

This is something we considered for CH in the past =E2=80=94 "I want to = scope my hints to a subpath" =E2=80=94 but punted on due to limited (or so = we deemed at the time, at least) utility vs implementation complexity trade= off (equivalent to cookie paths, which is a burden we didn't want to take o= n). In the last few years of CH experiments, I've not heard any complaints = or requests for this. I think that was the right call, and I'd suggest we s= tick with it.

Type

fwiw, I'd like to make an argument that we should omit this. The idea he= re is to enable sites to trigger a permission prompt via a header, which se= ems convenient on the surface, but experience shows that this is a bad UX p= attern: you should be using JS API to trigger permiss= ion prompt after explaining the intent and motivation. The incremental = value we're adding with the header trigger is low, and seems more like a fo= otgun.

If you buy both of the above, then CH has all the necessary building blo= cks to enable Geolocation.


@luisbar= gu WDYT? How critical, or not, are Path and Type for the use case you h= ad in mind?

@yoavwei= ss curious to hear your thoughts on the above, and Geolocation use case= for CDNs.

@mnot tac= tical question: what's the right process for followup RFC's to "register" h= ints to be compatible with Accept-CH? Do we need any extra steps in CH for = a registry, or some extension hooks?

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyFIU0c0IJif= 7LyroHxRj7nLJ-hWHks5sKByzgaJpZM4OJSIe">mute the thread.3D""

= ----==_mimepart_595976b3d5565_66a13fac91c55c384718-- From nobody Mon Jul 3 12:08:15 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.616 X-Spam-Level: X-Spam-Status: No, score=-0.616 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=MzohrS74turIr34NW3rRsCrWb9k=; b=mCaCGM7eDpzq+1SL qLNo8vScOCYqlcm4mU7zH90c37roYX4xTjN7eNfOy0klwP88JdMOEEeBKIPBIzdj 9RKESjJjjwHKACVaQplmdv1RKEEkduxMet99UZuuc4TovuIW4EbI8uoJUcZRJE7h FY15L9GVlgxyVrQ4+CfYCLLhQwQ= Date: Mon, 03 Jul 2017 19:08:09 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Julian's feedback (#350) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595a9619af3b5_55283f7f07b5bc2c24278a"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 03 Jul 2017 19:08:14 -0000 ----==_mimepart_595a9619af3b5_55283f7f07b5bc2c24278a Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit > Maybe add a full example, including a request/response pair for the case when "immutable" is not present? I actually toyed with this originally and decided the current arrangement was better. Drawing the absence of a request (or the case when nothing is different from the 723x state) didn't really clarify the normative text. It turned out better to just focus on the syntax of immutable in a response imo. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/350#issuecomment-312716013 ----==_mimepart_595a9619af3b5_55283f7f07b5bc2c24278a Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

Maybe add a full example, including a request/response pair for the case= when "immutable" is not present?

I actually toyed with this originally and decided the current arrangemen= t was better. Drawing the absence of a request (or the case when nothing is= different from the 723x state) didn't really clarify the normative text. I= t turned out better to just focus on the syntax of immutable in a response = imo.

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyE9zCSHJTRM= etZcK03TA6lFwolT4ks5sKTwZgaJpZM4NjLvn">mute the thread.3D""

= ----==_mimepart_595a9619af3b5_55283f7f07b5bc2c24278a-- From nobody Mon Jul 3 12:21:14 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.473 X-Spam-Level: X-Spam-Status: No, score=-5.473 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Mon, 03 Jul 2017 12:20:57 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1499109657; bh=eOW+tE/eclWDAC7L5EdmapCAbQtD5g/lLoNyMcNCLvA=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=a+UDFmW2dFm1wl7J1+Z1mMQ6s7rwmKDtFNwOH85N2CZhUhqE0IbxziPYK4aoPg7wT Xr95sX07u+O5Ufzaf2dPNbgtZmZS88oQKdXhNx6SnytIwHE3ruMBRlxzDfy/f26DSn fi97PKVyylB+l55Qjljp1CRUS46UTqoOaG+qWnSc= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Julian's feedback (#350) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595a9919e5ac1_6d7c3f9088373c3458326"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 03 Jul 2017 19:21:03 -0000 ----==_mimepart_595a9919e5ac1_6d7c3f9088373c3458326 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit remainder addressed in -03. thanks -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/350#issuecomment-312717909 ----==_mimepart_595a9919e5ac1_6d7c3f9088373c3458326 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

remainder addressed in -03. thanks


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_595a9919e5ac1_6d7c3f9088373c3458326-- From nobody Mon Jul 3 12:21:20 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.181 X-Spam-Level: X-Spam-Status: No, score=-8.181 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Mon, 03 Jul 2017 12:20:58 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1499109658; bh=c1kwkKaZYEpE5kcwNor+NeaRqjF+ttkS2s8Fewx1GFg=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=ABTcxxAJo5p81+G9fqyR9TrJsBLlPijcm6Q4A2jOuTZzaDi4j5DF+7E/HN5i3ywz6 FgwVtw6tiHEFdsK/EkP+lEvegxAO2NT6B37+AUAM+dAp60OK/wpbhrSuc3G6NG2nYg ihhkMtqdRsKLdZZ5yRBpi0vq7C2BneaQ+ntGE/bk= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Julian's feedback (#350) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595a991a79523_ca23f93e3b4dc30298d3"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 03 Jul 2017 19:21:04 -0000 ----==_mimepart_595a991a79523_ca23f93e3b4dc30298d3 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #350. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/350#event-1148608867 ----==_mimepart_595a991a79523_ca23f93e3b4dc30298d3 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #350.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_595a991a79523_ca23f93e3b4dc30298d3-- From nobody Mon Jul 3 12:21:35 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.381 X-Spam-Level: X-Spam-Status: No, score=-5.381 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Mon, 03 Jul 2017 12:21:12 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1499109672; bh=pwhtjSbzend/ZxihIVwwwCKVl48NmoX5S4riira+zfg=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=0QFx3FIdMgF4/6CUejTMkJvHXOWl9KChVlRzFpVuJTDlrMb3CNwBA4Xk131SAzbUx 42626ivSRHquTLjxUGqndl8IvczgSFbOTRKLTyvL4JqYvVCaPAquh9WLjkzV8AjOwF S4AizUvrf5p6kUh7OarqK+qMoqLPmJaFnMo6dG6s= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Immutable references (#351) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595a992898698_60313fa07fc4dc2c85356"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 03 Jul 2017 19:21:33 -0000 ----==_mimepart_595a992898698_60313fa07fc4dc2c85356 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #351. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/351#event-1148609106 ----==_mimepart_595a992898698_60313fa07fc4dc2c85356 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #351.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_595a992898698_60313fa07fc4dc2c85356-- From nobody Mon Jul 3 12:21:46 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.254 X-Spam-Level: X-Spam-Status: No, score=-3.254 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=iR8XvQbRwiegTfxNwflMwRcoEhE=; b=w5fAisiRKlCAjooB ApDGZqTkBinvu3reEq43Yql+f3ZXMMUT86NGToOVC8eR7boVWrtPuD4cRfjM+W9w xrVyksYDg58g7+wLk8sbujjAS/d354ochfaNlT4gkoUW9LNoc861Hfo6Whh3BMLU k1/2L++tESaCCGN9X2bg2mdijNI= Date: Mon, 03 Jul 2017 19:21:13 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Immutable references (#351) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595a9928d6346_3d0d3f9088373c34118464"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 03 Jul 2017 19:21:37 -0000 ----==_mimepart_595a9928d6346_3d0d3f9088373c34118464 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit addressed in -03. thanks -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/351#issuecomment-312717953 ----==_mimepart_595a9928d6346_3d0d3f9088373c34118464 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

addressed in -03. thanks


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_595a9928d6346_3d0d3f9088373c34118464-- From nobody Tue Jul 4 12:32:31 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -6.52 X-Spam-Level: X-Spam-Status: No, score=-6.52 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Tue, 04 Jul 2017 12:32:26 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1499196746; bh=xRMzt/0cOHydJK0YliHamnBhuBVkGFr0nngQuzcpyqA=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=Ey1g/jTila4fQBcbCDL9nzpTRHckfH2CW2oaINSj0etNXL5/lqtAlpWtC4TxzOQmt x+V38dIgIlpQV4HY7pfOYC56tC4Z69KYkxueuN5IsBmLkemQwCkd8MnkjrpYdt2/A1 ROj9naz0NbTqGQZG/vm6NPC3hr1W4qD0+CmdAfhE= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Geolocation Header (#364) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595bed4adc670_5e463f99d7087c34462f2"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 04 Jul 2017 19:32:30 -0000 ----==_mimepart_595bed4adc670_5e463f99d7087c34462f2 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit I still feel path can be useful, mainly to not "over-send" data that in this case might be sensitive from a privacy point of view. But I also understand the complexity tradeoffs, and Path is not core to this proposal. So if you went through this for CH and considered path was not worth, it probably applies well to this case. Regarding Type to trigger prompts... Right, it's doable through JS but was nice to offer a purely http based solution. Also understand the tradeoff in this case for value vs complexity, and agree it's also not core to the geolocation header. So on my side, if others think CH is the right approach for this, then for consistency and simplicity I'd be happy to follow that path and start a draft, on top of CH. Happy to hear other opinions :) -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/364#issuecomment-312938749 ----==_mimepart_595bed4adc670_5e463f99d7087c34462f2 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

I still feel path can be useful, mainly to not "over-send" data that i= n this case might be sensitive from a privacy point of view. But I also u= nderstand the complexity tradeoffs, and Path is not core to this proposal= . So if you went through this for CH and considered path was not worth, i= t probably applies well to this case.

Regarding Type to trigger prompts... Right, it's doable through JS but= was nice to offer a purely http based solution. Also understand the trad= eoff in this case for value vs complexity, and agree it's also not core t= o the geolocation header.

So on my side, if others think CH is the right approach for this, then= for consistency and simplicity I'd be happy to follow that path and star= t a draft, on top of CH. Happy to hear other opinions :)

&m= dash;
You are receiving this because you are subscribed to this thre= ad.
Reply to this email directly, view it on GitHub, or mute the thread.

=
= ----==_mimepart_595bed4adc670_5e463f99d7087c34462f2-- From nobody Wed Jul 5 16:14:29 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.182 X-Spam-Level: X-Spam-Status: No, score=-3.182 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=9uPP79Qo5o2fF9y5hToCgXvfGT4=; b=FN9rEieP4IwrwMnl zlby7H9AZqXrHSLwZvFnK2EcDXkgCEE0BpasS7kOgT3HPXmfp+kL6HsjFL/ZIqtq nwazBzl+bbLY6NeXDWp7bSbQaABf+EioiEEtrjKHphcKJLess0tovuiOUSsTskLg cGCkgaqcYn4w0W0tOAO6nP7JAFc= Date: Wed, 05 Jul 2017 23:14:16 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed Subject: [httpwg/http-extensions] No multiple headers with the same name (#365) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595d72c794ad1_72013f8b2c0d3c3817708c"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 05 Jul 2017 23:14:29 -0000 ----==_mimepart_595d72c794ad1_72013f8b2c0d3c3817708c Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit I just noticed that you have 2 `Link` headers in the same response. According to 7230: > A sender MUST NOT generate multiple header fields with the same field > name in a message unless either the entire field value for that > header field is defined as a comma-separated list [i.e., #(values)] > or the header field is a well-known exception (as noted below). -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/365 ----==_mimepart_595d72c794ad1_72013f8b2c0d3c3817708c Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

I just noticed that you have 2 Link headers in the same response. According to 7230:

A sender MUST NOT generate multiple header fields with the same field
name in a message unless either the entire field value for that
header field is defined as a comma-separated list [i.e., #(values)]
or the header field is a well-known exception (as noted below).


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_595d72c794ad1_72013f8b2c0d3c3817708c-- From nobody Wed Jul 5 16:15:04 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.254 X-Spam-Level: X-Spam-Status: No, score=-3.254 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=lhul+vSxh0Kghhq4BSxPxOEOo08=; b=DjZTbOc9gwwcQGxr Oc8nSZ3gqIKutCbkgRP+ZftRsyaNndbtRDa7Mt8IXBxX6tH5toZJKshcAIHGz+kv xtfzN4Lr1xmHnGZRXEtOsN1t3oexdSmI6Ztv7j6k4AX0Eq+33k2CpzPdBs44JgRX l+EcQF5ESGv/SDBYboDXDKtn3Ug= Date: Wed, 05 Jul 2017 23:14:59 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] No multiple headers with the same name (#365) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595d72f25d801_2b703fce546fbc3016465a"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 05 Jul 2017 23:15:02 -0000 ----==_mimepart_595d72f25d801_2b703fce546fbc3016465a Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit This is for Early Hints draft, not sure how I can put labels. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/365#issuecomment-313251974 ----==_mimepart_595d72f25d801_2b703fce546fbc3016465a Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

This is for Early Hints draft, not sure how I can put labels.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_595d72f25d801_2b703fce546fbc3016465a-- From nobody Wed Jul 5 16:16:50 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.181 X-Spam-Level: X-Spam-Status: No, score=-8.181 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Wed, 05 Jul 2017 16:16:46 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1499296606; bh=i/WKsWNeaV1ma+46teJvnhkg4pmPv/Te81+CTLlufJk=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=JvUM5d9aHx+6YB+V/3OhnjWUf6I50xiSsesOcFecbm03Rl0rpGRH2HvnPSTsmq+RG BRjwwQdVCxfQacQDDa8lcu0EvhUVnuRca90OrK5H2MFPHX48azbZ4XQdB+GouBz009 IaC1tjS9y9h6U5hvgMDeXWMNQcOtEC6mg/8KBVLg= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] No multiple headers with the same name (#365) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595d735e9a8d9_2a1e3ff6dbccfc381218c9"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 05 Jul 2017 23:16:49 -0000 ----==_mimepart_595d735e9a8d9_2a1e3ff6dbccfc381218c9 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Yes, but `Link` is defined by RFC5988 as: ``` Link = "Link" ":" #link-value ``` i.e., it uses the comma-separated list syntax. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/365#issuecomment-313252298 ----==_mimepart_595d735e9a8d9_2a1e3ff6dbccfc381218c9 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Yes, but Link is defined by RFC5988 as:

  Link           = "Link" ":" #link-value

i.e., it uses the comma-separated list syntax.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_595d735e9a8d9_2a1e3ff6dbccfc381218c9-- From nobody Wed Jul 5 16:16:59 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.182 X-Spam-Level: X-Spam-Status: No, score=-3.182 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=HwBIuUT9KfZBankZVbVNJXilPU4=; b=tqwER5P6w7RS+hKC 5ddXpnoSDFGH+kE0jmm5CoHIvfOJ5G2PkbIYnDEV//TmJBjUMmFEcOUogEzEQg80 hkqJCDkq2H3q32+1Igj92yRN9w0D9AZ/tCPuHjdp6aW4DhXlD91SKVl0ibbGKmst w4rgdrGon0ZV7jWycKf/a/EaJbo= Date: Wed, 05 Jul 2017 23:16:49 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] No multiple headers with the same name (#365) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595d73618f2bf_12db3f96784bbc2c965db"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 05 Jul 2017 23:16:52 -0000 ----==_mimepart_595d73618f2bf_12db3f96784bbc2c965db Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #365. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/365#event-1151829724 ----==_mimepart_595d73618f2bf_12db3f96784bbc2c965db Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #365.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_595d73618f2bf_12db3f96784bbc2c965db-- From nobody Wed Jul 5 16:18:58 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.253 X-Spam-Level: X-Spam-Status: No, score=-8.253 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Wed, 05 Jul 2017 16:18:54 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1499296734; bh=9GYrVzHFJO0FSxrkbtyllYBnLfPTwrLHf6znOJvAQN4=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=KxEOEt7X7nCXVwLHrY2jTkhaRWYeaUuG3+bPSkLge5iUK4nHdYSfRjl5HE6ftUPjw lXsZYef4094i0We8Tt527uKMhdfzH2NrISAe70awsOl2ruXIL61RPNpECewyFSUAE9 n0AhQqESvypThGhHHtJatICNwr0uTifLZcxl7puE= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] No multiple headers with the same name (#365) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595d73dedeb5a_2d813fa24a86fc3c1781da"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 05 Jul 2017 23:18:57 -0000 ----==_mimepart_595d73dedeb5a_2d813fa24a86fc3c1781da Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit right. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/365#issuecomment-313252618 ----==_mimepart_595d73dedeb5a_2d813fa24a86fc3c1781da Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

right.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_595d73dedeb5a_2d813fa24a86fc3c1781da-- From nobody Thu Jul 6 20:29:30 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.182 X-Spam-Level: X-Spam-Status: No, score=-3.182 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=qIpRHHwFr4QCDA8eeBH1+Nbg8/o=; b=NTUdxUZ+wtftliA+ tXytnMONOuZO/DCSWHMP+T7wAzvtz68OYWvkeBPWXqg+Dvttr0Ut7azT2FIlCArS 02iWxwtQoX83RRLVLgB6X4+De862jSzr5UnII08TuBM+laRKW1Lf9PTaPTtilJPc HKE5dcCsWkfvSONLjiCjVmsQoDY= Date: Fri, 07 Jul 2017 03:29:26 +0000 (UTC) To: httpwg/http-extensions Cc: Push In-Reply-To: References: Subject: Re: [httpwg/http-extensions] fix contradictory definintions with HTTP/1.1 (#363) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595f00169d76b_67793f90fd0a5c3082139"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 07 Jul 2017 03:29:29 -0000 ----==_mimepart_595f00169d76b_67793f90fd0a5c3082139 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @kazuho pushed 2 commits. 68210e9 Merge branch 'master' into kazuho/early-hints/wglc d0903d6 multiple 103s -- You are receiving this because you are subscribed to this thread. View it on GitHub: https://github.com/httpwg/http-extensions/pull/363/files/0154cce7e09b89ac93aa7135b956588818efc3c1..d0903d61c8e591c800ca22534dd3e46b761737ec ----==_mimepart_595f00169d76b_67793f90fd0a5c3082139 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@kazuho pushed 2 commits.

  • 68210e9 Merge branch 'master' into kazuho/early-hints/wglc
  • d0903d6 multiple 103s


You are receiving this because you are subscribed to this thread.
View it on GitHub or mute the thread.

----==_mimepart_595f00169d76b_67793f90fd0a5c3082139-- From nobody Thu Jul 6 20:30:21 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.182 X-Spam-Level: X-Spam-Status: No, score=-3.182 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=9the6B8CCiHuOGp/hS0zN/jT3co=; b=DOfhG5l9jLuRBQTh TgJreETXzSryUTlxa7Hr3fAj0RuXOTqbDWqEyFpxJGg+6rZ1B8OYncWZWK695+Nk DyP4VHyh5eTktqcYzFnUjlxd+iM6NEwFnusw4PkVTC+VYVFZhGLGZ55dYbDexu7f vnnH1+H5YlxwrKbjzVmKwFoir2U= Date: Fri, 07 Jul 2017 03:30:17 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] fix contradictory definintions with HTTP/1.1 (#363) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_595f0049462_52443f8c4acbdc3c1490ea"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 07 Jul 2017 03:30:19 -0000 ----==_mimepart_595f0049462_52443f8c4acbdc3c1490ea Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @wtarreau Thank you for the answer. Adopted the text (with nits) in d0903d6. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/363#issuecomment-313578025 ----==_mimepart_595f0049462_52443f8c4acbdc3c1490ea Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@wtarreau Thank you for the answer. Adopted the text (with nits) in d0903d6.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_595f0049462_52443f8c4acbdc3c1490ea-- From nobody Fri Jul 7 19:21:17 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -2.021 X-Spam-Level: X-Spam-Status: No, score=-2.021 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=E6W57B+4RmcH0qIzU181JulBeoA=; b=QSCzrTb5I/KHOmX0 7BNM4S7QRW5ibBOIhGRwahXIbWqw7JRjrQJF4A8jeKcezH02KHK+KgXz9/FAkE6D WdRAdE2rh6+cJ+j5s0VbyKrrF8utz8VnMFuOw7JCdzkzzwbA80zrkj9I966A3jSX U64YfUhAO+F98aK7lbAMx0HH+Vs= Date: Sat, 08 Jul 2017 02:21:12 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Consulting the DNS on expanding ORIGIN set? (#330) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_5960419819cb3_456f3ffcda08bc384768c"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 08 Jul 2017 02:21:16 -0000 ----==_mimepart_5960419819cb3_456f3ffcda08bc384768c Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit > I'm trying to understand your second concern WRT operational behavior of clients. The origins being added are explicitly nominated by the server; presence in the certificate is not enough to cause the connection to be used (indeed, that concern was a large part of the motivation of this draft). I believe that limiting origin-set and connection reuse was the original motivation for this draft, however, it seems that possible use cases changed a bit because of [draft-bishop-httpbis-http2-additional-certs](https://datatracker.ietf.org/doc/html/draft-bishop-httpbis-http2-additional-certs), which together with this draft, makes it possible to expand the origin-set and effectively hijack traffic for all domains that server has valid SSL certificates for. Even ignoring the compromised server scenario, there are at least a few operational issues with bypassing DNS: 1. Many medium to large companies use multiple CDN providers and steer traffic using DNS. They use either custom GeoDNS solutions or services like [Cedexis](https://www.cedexis.com/solutions/multi-cdn/) to load balance traffic across multiple CDNs, or simply use one of the CDNs as the primary and rest as active backups. All those CDNs have valid SSL certificates, so neither CT nor certificate pinning would help. Similarly, some websites migrate traffic to DDoS protection services only during attacks, but those services are configured and have valid SSL certificates at all times. **Basically, configured != active.** 2. Servers with wildcard certificates can takeover all traffic for the domain, even if some subdomains would never be routed to a particular server. To give an extreme example, let's say that `www.bank.com`, `promotions.bank.com`, etc. are served by the CDN, but `secure.bank.com` is handled by the bank's own infrastructure. There is nothing stopping the CDN with valid certificate for `*.bank.com` from hijacking the traffic for `secure.bank.com`, and while certificate pinning would prevent traffic for `secure.bank.com` from reaching the CDN, it would effectively result in DoS and pretty bad end-user experience. One solution that came up in discussions with @grittygrease and @enygren, was to include signed DNSSEC response in the `ORIGIN` frame, to prove that the traffic should be routed to this particular server. This obviously solves only part of the problem, since it doesn't mean that traffic from _this particular client_ would be routed to that server, but it's much better than servers going completely wild. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/330#issuecomment-313827663 ----==_mimepart_5960419819cb3_456f3ffcda08bc384768c Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

I'm trying to understand your second concern WRT operational behavior of= clients. The origins being added are explicitly nominated by the server; p= resence in the certificate is not enough to cause the connection to be used= (indeed, that concern was a large part of the motivation of this draft).

I believe that limiting origin-set and connection reuse was the original= motivation for this draft, however, it seems that possible use cases chang= ed a bit because of draft-bishop-httpbis-http2-additiona= l-certs, which together with this draft, makes it possible to expand th= e origin-set and effectively hijack traffic for all domains that server has= valid SSL certificates for.

Even ignoring the compromised server scenario, there are at least a few = operational issues with bypassing DNS:

  1. Many medium to large companies use multiple CDN providers and steer traf= fic using DNS. They use either custom GeoDNS solutions or services like Cedexis to load b= alance traffic across multiple CDNs, or simply use one of the CDNs as the p= rimary and rest as active backups. All those CDNs have valid SSL certificat= es, so neither CT nor certificate pinning would help.
    Similarly, some websites migrate traffic to DDoS protection services only d= uring attacks, but those services are configured and have valid SSL certifi= cates at all times.
    Basically, configured !=3D active.

  2. Servers with wildcard certificates can takeover all traffic for the doma= in, even if some subdomains would never be routed to a particular server. T= o give an extreme example, let's say that www.bank.com, = promotions.bank.com, etc. are served by the CDN, but secure.ba= nk.com is handled by the bank's own infrastructure. There is nothing= stopping the CDN with valid certificate for *.bank.com from h= ijacking the traffic for secure.bank.com, and while certificat= e pinning would prevent traffic for secure.bank.com from reach= ing the CDN, it would effectively result in DoS and pretty bad end-user exp= erience.

One solution that came up in discussions with @grittygrease and @enygren, was to incl= ude signed DNSSEC response in the ORIGIN frame, to prove that = the traffic should be routed to this particular server. This obviously solv= es only part of the problem, since it doesn't mean that traffic from th= is particular client would be routed to that server, but it's much bet= ter than servers going completely wild.

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyBWPOg1k8Gm= 0J_4Ua-sB3DLrGO_Cks5sLueYgaJpZM4NEzUM">mute the thread.3D""

= ----==_mimepart_5960419819cb3_456f3ffcda08bc384768c-- From nobody Sat Jul 8 22:41:57 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.616 X-Spam-Level: X-Spam-Status: No, score=-0.616 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=AZA9SUG/vOQU/Gig613QdZeB0qA=; b=MyJU44bIh/rBEr1N pgrX8aH1fRm/m2lKKHdhBWkdZk+SFdC9QtKBCdV4T7v7FC2JiFPaO1HFEQBlZkf3 nws7jwdHSmbtYGL4mNkGSEbE/4EKCJpI5clhHpoqUCjD9pO1fA5ZhDf6SHhy1bG0 Gh7BvXhYFx0RfOPlU9yzBdq7OCE= Date: Sun, 09 Jul 2017 05:41:52 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Consulting the DNS on expanding ORIGIN set? (#330) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_5961c22095888_378e3fca64cd3c3c87879"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 09 Jul 2017 05:41:55 -0000 ----==_mimepart_5961c22095888_378e3fca64cd3c3c87879 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @PiotrSikora - thanks for the input. WRT global load balancing / CDN balancing -- one of the things that has been discussed is a bit to tell the client whether or not to check DNS; that would allow them to use this, I think. WRT wildcards -- ORIGIN doesn't currently support wildcarding. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/330#issuecomment-313900441 ----==_mimepart_5961c22095888_378e3fca64cd3c3c87879 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

@Piotr= Sikora - thanks for the input.

WRT global load balancing / CDN balancing -- one of the things that has = been discussed is a bit to tell the client whether or not to check DNS; tha= t would allow them to use this, I think.

WRT wildcards -- ORIGIN doesn't currently support wildcarding.

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyKOamKq3uAl= S05O7KctzYj8W3IkYks5sMGgggaJpZM4NEzUM">mute the thread.3D""

= ----==_mimepart_5961c22095888_378e3fca64cd3c3c87879-- From nobody Mon Jul 10 14:58:25 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -4.801 X-Spam-Level: X-Spam-Status: No, score=-4.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=cq3Qe0c+7WR0a7HURNuvJcR/PR0=; b=c01oEHArL63+N0XH cUuvw6N12ZDvjyNlGF6cXYnnQfbBRnTMeuSuBgLmnVugQxoTXWyI+UCi1vDCOf9G 9wzBEgeeJsXXm4vwKx4pvFyBpjrhRpKt4POwdyoWztvE/vHmtiXCve4y6ryqIP9Y JZad/x3qgZAnhvkctHFfHC80YPs= Date: Mon, 10 Jul 2017 21:58:07 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Consulting the DNS on expanding ORIGIN set? (#330) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_5963f86f2c8e0_26933ffbe8b61c2c1767bb"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 10 Jul 2017 21:58:23 -0000 ----==_mimepart_5963f86f2c8e0_26933ffbe8b61c2c1767bb Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Even without supporting wildcard ORIGINs, @PiotrSikora has a valid point that if a server has a wildcard cert it can pull in any hostnames that it wants to. Telling a client whether or not to check DNS certainly helps for some of these cases (ie, it helps avoid a few operational snafus) but doesn't help against malicious use-cases. My inclination is still to pull this draft back to the original "limiting origin set and connection reuse" scenario but while leaving placeholders for a subsequent draft that would cover expanding the origin set (ie, with using additional-certs and whatever other mitigators are deemed appropriate). Otherwise this draft changes the operational model of the web much more substantially than people may realize at first glance. Any operational shift this significant likely wants to be a first-class discussion rather than being a side-effect of a draft that initially had a much more constrained scope. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/330#issuecomment-314261805 ----==_mimepart_5963f86f2c8e0_26933ffbe8b61c2c1767bb Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

Even without supporting wildcard ORIGINs, @PiotrSikora has a valid point that= if a server has a wildcard cert it can pull in any hostnames that it wants= to.

Telling a client whether or not to check DNS certainly helps for some of= these cases (ie, it helps avoid a few operational snafus) but doesn't help= against malicious use-cases.

My inclination is still to pull this draft back to the original "limitin= g origin set and connection reuse" scenario but while leaving placeholders = for a subsequent draft that would cover expanding the origin set (ie, with = using additional-certs and whatever other mitigators are deemed appropriate= ). Otherwise this draft changes the operational model of the web much more= substantially than people may realize at first glance. Any operational sh= ift this significant likely wants to be a first-class discussion rather tha= n being a side-effect of a draft that initially had a much more constrained= scope.

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyGw18H3uESk= S2rbNSh5z0tSxlDxoks5sMp5vgaJpZM4NEzUM">mute the thread.3D""

= ----==_mimepart_5963f86f2c8e0_26933ffbe8b61c2c1767bb-- From nobody Mon Jul 10 15:31:45 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.182 X-Spam-Level: X-Spam-Status: No, score=-8.182 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Mon, 10 Jul 2017 15:31:41 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1499725901; bh=MwLDKoo9Qi9NCLDG72oIkllNJDf77U7lcGMrOW8MNz8=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=zxPCki3FhmdOwGy4df7dfZmmPWha/5+7BwoFz2G3qlIe1QeHv57xnyy3+k+6bnoqP WOCInh+3vDIu5cUsEIAM6hE3IWkT6r4VjrkWJ+fQUGDGSdyetGJ6oXRJTwUl+8umUP Eo9R7JTmUjLWYXQyD7h69iinq6ZdLmqJ8dwmNRzA= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Consulting the DNS on expanding ORIGIN set? (#330) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_5964004d1983e_34093f936acf1c2c64641"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 10 Jul 2017 22:31:44 -0000 ----==_mimepart_5964004d1983e_34093f936acf1c2c64641 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit wrt "check DNS" flag - it's still the server (i.e. CDN) that's making this recommendation to the client, right? If so, then I don't think it fixes anything, since CDNs can omit this flag and prevent clients from consulting DNS, justifying this with "we're improving the performance" excuse. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/330#issuecomment-314268696 ----==_mimepart_5964004d1983e_34093f936acf1c2c64641 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

wrt "check DNS" flag - it's still the server (i.e. CDN) that's making = this recommendation to the client, right? If so, then I don't think it fi= xes anything, since CDNs can omit this flag and prevent clients from cons= ulting DNS, justifying this with "we're improving the performance" excuse= .

&m= dash;
You are receiving this because you are subscribed to this thre= ad.
Reply to this email directly, view it on GitHub, or mute the thread.

=
= ----==_mimepart_596417b88168b_45bc3fc061f73c385475-- From nobody Mon Jul 10 21:15:28 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.253 X-Spam-Level: X-Spam-Status: No, score=-8.253 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Mon, 10 Jul 2017 21:15:25 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1499746525; bh=/0sHOIuizL+ysJPwISeafn5Ynmgob71nlOBdnMhL/WY=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=J+g5IU22gzaUKIaJLaz+H7r7lopIHW2m8/7Tf2A+Cqg1LNg8Hy63rVf3r/MLKykyu XTuofokHstoAC3PDGrBnMJyKSeXk0fO4Bjvh8UqePpiatJr8D+er/3gEIke81+mLyN S4Uy5G0HuaLP8pFo62+qzCbT8ZKHutgxHFOa6byk= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] fix contradictory definintions with HTTP/1.1 (#363) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596450ddd8f0a_218df3fba15befc3088487"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 11 Jul 2017 04:15:28 -0000 ----==_mimepart_596450ddd8f0a_218df3fba15befc3088487 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit mnot approved this pull request. Looks good to me! -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/363#pullrequestreview-49088818 ----==_mimepart_596450ddd8f0a_218df3fba15befc3088487 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@mnot approved this pull request.

Looks good to me!


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596450ddd8f0a_218df3fba15befc3088487-- From nobody Mon Jul 10 22:59:47 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: 0.098 X-Spam-Level: X-Spam-Status: No, score=0.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=UeUsCfc/B6W8ns28MixDviQeWdE=; b=mc6bMTcuWVtxr+Rm iv68546d7pmW8xbyi+GY+LW8MmYmO7OElLf+m8M4GEX1V3/rBvogn+GEv/GLg2IM NzM8/lbtcsg4aVK72u1RypuLOF+BSA8kxl3ttnow72L+2NkFpx7SslM1yUFdBwkK 1ro3bffc5xUnhUXp5Zt+Gdgdq78= Date: Tue, 11 Jul 2017 05:59:44 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] fix contradictory definintions with HTTP/1.1 (#363) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_59646950ae187_47483f8053ac9c30106759"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 11 Jul 2017 05:59:47 -0000 ----==_mimepart_59646950ae187_47483f8053ac9c30106759 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Merged #363. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/363#event-1158116035 ----==_mimepart_59646950ae187_47483f8053ac9c30106759 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Merged #363.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_59646950ae187_47483f8053ac9c30106759-- From nobody Mon Jul 10 23:04:38 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.474 X-Spam-Level: X-Spam-Status: No, score=-0.474 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=s1lg3yOVmklcxUlEwz71jMNmo9I=; b=bfCeCQB964MCsXBz oE/v1TNOCEho+prb0PpzUc6vbQQH1KlDghSifXzsQBv51mZqPdpG8okvb4vuVA5Q 9pXNUz/m6tkDSEUrbh+xXLpKZYL92JgpRgmsg+dwy/N0QQPJeeM1mDf35xyYW7DN ZbAJP15fQMNlQJpJq7tQDN+vBE0= Date: Tue, 11 Jul 2017 06:04:33 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] fix contradictory definintions with HTTP/1.1 (#363) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_59646a70b0b12_1b8e3f7fc89cdc2c813e2"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 11 Jul 2017 06:04:37 -0000 ----==_mimepart_59646a70b0b12_1b8e3f7fc89cdc2c813e2 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @mnot Thank you for the review! -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/363#issuecomment-314336821 ----==_mimepart_59646a70b0b12_1b8e3f7fc89cdc2c813e2 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@mnot Thank you for the review!


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_59646a70b0b12_1b8e3f7fc89cdc2c813e2-- From nobody Thu Jul 13 08:00:33 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.616 X-Spam-Level: X-Spam-Status: No, score=-0.616 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=1+KCfotS/95L1y1Y1esp7vtYKmw=; b=jTwlurU6oB3kUGZa Rj+MpHG4d/KoHVwHlbDQpfxvARHiKFsO4go2/7hz4kJSgi9PLXl4B7QJ4+SgWbmv WnhxDDmRhS+rWMsanPWeeqdQQNrHln+ELHsFqmqtXCIDrBN0Dz0N5aPG3tNDLd0x pEglP0S1kOsWYwwZfoSUsgX9tRQ= Date: Thu, 13 Jul 2017 15:00:23 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Geolocation Header (#364) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_59678b07c43b_78473f8040e49c38213585"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 13 Jul 2017 15:00:32 -0000 ----==_mimepart_59678b07c43b_78473f8040e49c38213585 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit One major difference between this and the other CH headers is that this header should only be sent to the first party (or only to hosts which have permission to view geolocation data, so to third parties that got such permissions before). The use case of using geo info for content adaptation at the edge or origin seems an interesting one. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/364#issuecomment-315104444 ----==_mimepart_59678b07c43b_78473f8040e49c38213585 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

One major difference between this and the other CH headers is that this = header should only be sent to the first party (or only to hosts which have = permission to view geolocation data, so to third parties that got such perm= issions before).
The use case of using geo info for content adaptation at the edge or origin= seems an interesting one.

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyJqdycWcuwC= HLcJ8VwAPx1B5mJAUks5sNjEHgaJpZM4OJSIe">mute the thread.3D""

= ----==_mimepart_59678b07c43b_78473f8040e49c38213585-- From nobody Sun Jul 16 03:12:02 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -9.799 X-Spam-Level: X-Spam-Status: No, score=-9.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 16 Jul 2017 03:11:59 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500199919; bh=0hRdYpMVjjDc6S1PwVV0MvIDJzk3JqWQem7MvnuUqQY=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=oPxcio4V2INvmc+gLNEzDpr6rEeuAewkcqcVfBNpHk5mHPUG1IQ4jOxn3SUgSWgvb NPr+bpMeAkPWZ0oJXCP5qLaik6v21YwDt7nOgcilQJ2AW7Jujk+E+LTgP9lWezcjwM ic8rguZX/HCIAKamCYXlfKXj2CQh4fGzHppY+uJ0= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Consulting the DNS on expanding ORIGIN set? (#330) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596b3bef22875_4c213f9707c85c34286139"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 16 Jul 2017 10:12:01 -0000 ----==_mimepart_596b3bef22875_4c213f9707c85c34286139 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @martinthomson I originally wanted to dismiss this idea (since CDNs could mis-issue certs with the extension anyway, so it doesn't add 2nd factor). However, we chatted a bit about it with @grittygrease yesterday, and we came to conclusion that opt-in certificate extension, along with CT requirement (so that it would be obvious that CDN requested certificate with such extension, even when domain owner didn't opt-in for it) seems like an acceptable solution. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/330#issuecomment-315599316 ----==_mimepart_596b3bef22875_4c213f9707c85c34286139 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

@m= artinthomson I originally wanted to dismiss this idea (since CDNs cou= ld mis-issue certs with the extension anyway, so it doesn't add 2nd facto= r). However, we chatted a bit about it with @grittygrease yesterday, and we= came to conclusion that opt-in certificate extension, along with CT requ= irement (so that it would be obvious that CDN requested certificate with = such extension, even when domain owner didn't opt-in for it) seems like a= n acceptable solution.

&m= dash;
You are receiving this because you are subscribed to this thre= ad.
Reply to this email directly, view it on GitHub, or mute the thread.

=
= ----==_mimepart_596b3bef22875_4c213f9707c85c34286139-- From nobody Sun Jul 16 05:19:41 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.616 X-Spam-Level: X-Spam-Status: No, score=-5.616 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 16 Jul 2017 05:19:37 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500207577; bh=kV8fsjxBZSEC4v03V4IpzbqUfH+unEU4RBJUW/NVk1Y=; h=From:Reply-To:To:Cc:Subject:List-ID:List-Archive:List-Post: List-Unsubscribe:From; b=AVNJ5tqVpBF6fcx4ipxzP1oudYDpUnZRAIFitMrXZGMULAxoAesNTkNZJN2oq3Zuw KmjP5R0jrhMH4ZvdMrZ8VMUWV1BWqtQVCJ78heqcfDz8kmWcOx6CeBjk9eQcRlFRsN RMiwaZIeXcOPqGle4ItxTW0p7Z/E23Q6MNn2hXgc= To: httpwg/http-extensions Cc: Subscribed Subject: [httpwg/http-extensions] ORIGIN frame typos (#366) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596b59d9cfa0e_611c3f88c50b5c38902d1"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 16 Jul 2017 12:19:40 -0000 ----==_mimepart_596b59d9cfa0e_611c3f88c50b5c38902d1 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Make optionallity more like ALTSVC, make test less Gollum-like You can view, comment on, or merge this pull request online at: https://github.com/httpwg/http-extensions/pull/366 -- Commit Summary -- * ORIGIN frame typos -- File Changes -- M draft-ietf-httpbis-origin-frame.md (4) -- Patch Links -- https://github.com/httpwg/http-extensions/pull/366.patch https://github.com/httpwg/http-extensions/pull/366.diff -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/366 ----==_mimepart_596b59d9cfa0e_611c3f88c50b5c38902d1 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Make optionallity more like ALTSVC, make test less Gollum-like


You can view, comment on, or merge this pull request online at:

  https://github.com/httpwg/http-extensions/pull/366

Commit Summary

  • ORIGIN frame typos

File Changes

Patch Links:


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596b59d9cfa0e_611c3f88c50b5c38902d1-- From nobody Sun Jul 16 05:33:26 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.182 X-Spam-Level: X-Spam-Status: No, score=-8.182 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 16 Jul 2017 05:33:22 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500208402; bh=tOx2EbQDYThOAPWHQzvrvUNCZZOXe6ItuV853cs81/w=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=wt8eFI1P7h9pndp1FFX42y9UPs6q1RvJH/uDhtmEJIyJ61tsjYBQs5alIV4BhApBh hH4OAWSIqUKkuX716tIvTahYOa3bE0K0VdbC4qzjKMWBtmCdV+xHHxJOe6gqinUM9Q r6tinI6mFe0WRaR3TNb/QfBtK/EPhama8/AZp/IQ= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] ORIGIN frame typos (#366) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596b5d12a9886_1b9573f9c812dfc3c295be"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 16 Jul 2017 12:33:25 -0000 ----==_mimepart_596b5d12a9886_1b9573f9c812dfc3c295be Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Merged #366. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/366#event-1165567369 ----==_mimepart_596b5d12a9886_1b9573f9c812dfc3c295be Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Merged #366.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596b5d12a9886_1b9573f9c812dfc3c295be-- From nobody Sun Jul 16 05:33:35 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -2.755 X-Spam-Level: X-Spam-Status: No, score=-2.755 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=IqPj+cKw1FPIWMPydr1qq6mwOno=; b=fNHJNqkkPE76F41v 3DaoPG3twUl6fmUWahe1kaQSoK29BtscWbAzelgLuU9hYPL0T1PqXUX+kuc1zVPQ JpWD1zeLSR/wxpFBT764hTXpQcAkeJYkPk12phSBPKmBmWVigoShA+Kn1xuByGzh BloAyZTo4AhclTRudR6dx76v6Hs= Date: Sun, 16 Jul 2017 12:33:25 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] ORIGIN frame typos (#366) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596b5d15354fd_3ddb3f9707c85c3414202e"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 16 Jul 2017 12:33:28 -0000 ----==_mimepart_596b5d15354fd_3ddb3f9707c85c3414202e Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit thx -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/366#issuecomment-315606335 ----==_mimepart_596b5d15354fd_3ddb3f9707c85c3414202e Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

thx


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596b5d15354fd_3ddb3f9707c85c3414202e-- From nobody Sun Jul 16 08:07:13 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -2.683 X-Spam-Level: X-Spam-Status: No, score=-2.683 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=U/YJrMtZy7CLuUF/jXcawzloYCI=; b=VOWSkz0ygmJUSj59 caQjcTcad4BFKsk/6m5f6yTojoUjpi4qbl9Q+zJzIq6+54hadFf3IUzCQ5+OofQ8 pgFy4DOhGEntZeh3IY3wxaDPxNjaa6E7iMjlvi9lhpva4cEzwV916UeQgmyUSRBE GHgFBoMZAsDfjAGgIC2rBnq88m0= Date: Sun, 16 Jul 2017 15:07:01 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] update rfc2119 boilerplate (d7c6aa3) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596b8114ec15c_42d03f88c50b5c381720de"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 16 Jul 2017 15:07:12 -0000 ----==_mimepart_596b8114ec15c_42d03f88c50b5c381720de Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Please follow https://tools.ietf.org/html/rfc8174#section-2 -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/commit/d7c6aa391cd05ad2fc745d79d4f5e4d1a1a3b44f#commitcomment-23123235 ----==_mimepart_596b8114ec15c_42d03f88c50b5c381720de Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Please follow https://tools.ietf.org/html/rfc8174#section-2


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596b8114ec15c_42d03f88c50b5c381720de-- From nobody Sun Jul 16 08:16:15 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.097 X-Spam-Level: X-Spam-Status: No, score=-0.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_SORBS_SPAM=0.5, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=OonXxX2wnw5j7j4sD7RZd/qhIRA=; b=pcByrC1PY4XRN7g2 c3Vk9gVQbNdOZHpELJamVIWYskXDB5NkSRNe1zzacoaUMEWou3Dftl8UrasIOK0x 2RhWEdmi6vt3Dns/Q3iUkVYnvaw/OojCyiQR6EZc0oL6wMisshLVHbgOignjbfMB G1sWKTobZXI9O3cy2WHnBadM9gk= Date: Sun, 16 Jul 2017 15:16:11 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Julian's CH feedback (#359) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596b833b593ef_7a263fe031719c3c196f7"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 16 Jul 2017 15:16:14 -0000 ----==_mimepart_596b833b593ef_7a263fe031719c3c196f7 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit > I'm inclined to keep them as is. The CSS spec is CSS2, not CSS values specific, and other names are auto generated -- don't think it's worth overwriting. I think it's worthwhile to override names when those are clearly ugly because they're auto-generated (for instance, because they include a date that the reader will not care about at all). -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/359#issuecomment-315615925 ----==_mimepart_596b833b593ef_7a263fe031719c3c196f7 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

I'm inclined to keep them as is. The CSS spec is CSS2, not CSS values sp= ecific, and other names are auto generated -- don't think it's worth overwr= iting.

I think it's worthwhile to override names when those are clearly ugly be= cause they're auto-generated (for instance, because they include a date tha= t the reader will not care about at all).

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyCytu3lkXjh= Th_9U2qdmGz-ENxHuks5sOik7gaJpZM4N-8Es">mute the thread.3D""

= ----==_mimepart_596b833b593ef_7a263fe031719c3c196f7-- From nobody Sun Jul 16 09:14:56 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.116 X-Spam-Level: X-Spam-Status: No, score=-5.116 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 16 Jul 2017 09:14:51 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500221691; bh=3IsdluD2/40ymyvoUZecVj1pQS0nLlvHo1HYB3ydciw=; h=From:Reply-To:To:Cc:Subject:List-ID:List-Archive:List-Post: List-Unsubscribe:From; b=ZHYkXvlD+GP8PK6LKGtKeO5rhQMN7ndpgkQ+JHdNndFEAKwqqpDVyU+k/Ntfxgmwi 2yi8t59aonmh7XrOCfMb5gVIZoDJAw167xdoy6cYyiUASI98CXp8u3ggo3Ym+jm1ou W7U4mFr0MQ0n6EBlOm3CpJNtkXdo8XpwKnc1eMvE= To: httpwg/http-extensions Cc: Subscribed Subject: [httpwg/http-extensions] simplify reference anchors (#367) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596b90fbcea35_77e13fe031719c3c8005"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 16 Jul 2017 16:14:54 -0000 ----==_mimepart_596b90fbcea35_77e13fe031719c3c8005 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit You can view, comment on, or merge this pull request online at: https://github.com/httpwg/http-extensions/pull/367 -- Commit Summary -- * simplify reference anchors -- File Changes -- M draft-ietf-httpbis-client-hints.md (14) -- Patch Links -- https://github.com/httpwg/http-extensions/pull/367.patch https://github.com/httpwg/http-extensions/pull/367.diff -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/367 ----==_mimepart_596b90fbcea35_77e13fe031719c3c8005 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

You can view, comment on, or merge this pull request online at:

  https://github.com/httpwg/http-extensions/pull/367

Commit Summary

  • simplify reference anchors

File Changes

Patch Links:


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596b90fbcea35_77e13fe031719c3c8005-- From nobody Mon Jul 17 13:38:10 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.453 X-Spam-Level: X-Spam-Status: No, score=-5.453 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Mon, 17 Jul 2017 13:38:07 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500323887; bh=lQsMZ+3GdSEg0S7tHnV8eml1paD+Hee+cQcWgLH+jY8=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=rIdDQz8YJuL3vhpZfmQgF4jWtZPOErMnus4SafajxPTG1MMBQMqDGNIGb4InK7bI8 uksBBREw2nC+2dvcQikdFHSRp/cRCEjmPrWjj7UU1jDyCG0GoQXdfNjWbPrNDkVtg8 XEFFyMROR0gWXL5WoYZvblFuHL0qhEtHXQp9pms8= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] simplify reference anchors (#367) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596d202f5c27_72543fd12838bc2c73052"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 17 Jul 2017 20:38:09 -0000 ----==_mimepart_596d202f5c27_72543fd12838bc2c73052 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Thanks Julian! -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/367#issuecomment-315875736 ----==_mimepart_596d202f5c27_72543fd12838bc2c73052 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Thanks Julian!


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596d202f5c27_72543fd12838bc2c73052-- From nobody Mon Jul 17 13:38:18 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.382 X-Spam-Level: X-Spam-Status: No, score=-0.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=9/SAYchfq8zoaT/kxsB+0lkZUL4=; b=lNEDsuSZbQjJjscM ziDCbklQdRs7iF08sM3ueISVogKbwQ9pROeGadjR8xkB8SB/GZF77kNz1Z9XEVx1 s2pfG1QWwrxGzZ3HZh49mzWxs9OG/e85KcIKDr8p79YG2qzIzBhDeB4QHnblOC+z FcNGrd8Th1bsVorpUp58+a8u6Os= Date: Mon, 17 Jul 2017 20:38:12 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] simplify reference anchors (#367) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596d20342af43_3dd93fbedc53dc2c975d1"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 17 Jul 2017 20:38:14 -0000 ----==_mimepart_596d20342af43_3dd93fbedc53dc2c975d1 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Merged #367. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/367#event-1167193163 ----==_mimepart_596d20342af43_3dd93fbedc53dc2c975d1 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Merged #367.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596d20342af43_3dd93fbedc53dc2c975d1-- From nobody Mon Jul 17 13:38:30 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.254 X-Spam-Level: X-Spam-Status: No, score=-3.254 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=ruW9mS4CEmOba7E7/wqm6enXKE0=; b=InJ3Cd9rZHtcptV+ V4e32PV6ZaKpXLNgfbg7yC5OnQ5xUPkJrglr+VggKI7mJOQVb4F253qFlIee/lXn RcEnJZoeDCEnychWqgplJJztfdlW+j6PKBXiNO7cpc4K6IK4r8EIfeBMPs1IOizo OqJ5Bny9KMirphMRhXR5/hmn1DM= Date: Mon, 17 Jul 2017 20:37:53 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] simplify reference anchors (#367) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596d2020a7e45_73d3fcc15b8bc3c978b3"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 17 Jul 2017 20:38:29 -0000 ----==_mimepart_596d2020a7e45_73d3fcc15b8bc3c978b3 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit igrigorik approved this pull request. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/367#pullrequestreview-50440141 ----==_mimepart_596d2020a7e45_73d3fcc15b8bc3c978b3 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@igrigorik approved this pull request.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596d2020a7e45_73d3fcc15b8bc3c978b3-- From nobody Tue Jul 18 05:27:32 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -7.896 X-Spam-Level: X-Spam-Status: No, score=-7.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Tue, 18 Jul 2017 05:27:28 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500380849; bh=edigWfC/XQiOmvfu5P4FSMqV2HOSQA3JbmLsiSmDhkk=; h=From:Reply-To:To:Cc:Subject:List-ID:List-Archive:List-Post: List-Unsubscribe:From; b=u2mFFtTi3r8h/1m3RyeLl/JMQ6yPFGoGIjW+Bmtwn3VPsFluHz3sLmPgs76Z6rsSV TK78jCzSlZ/54ovKQebgRloZURPNZ4LTSxL+lEjNWj+HMHq1458fse6kUPOsqZZHL2 sTJ91DagyBtkYjJhz94fopUHBfSamhUNKdS4EpQs= To: httpwg/http-extensions Cc: Subscribed Subject: [httpwg/http-extensions] Repetition of Fields (#368) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596dfeb0f0b5e_c3403fda8e3b3c30199450"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 18 Jul 2017 12:27:31 -0000 ----==_mimepart_596dfeb0f0b5e_c3403fda8e3b3c30199450 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable >From Lucas: I naively assumed the ORIGIN frame was very similar to the ALTSVC frame, = I missed out on the repetition element. I think it would help to improve = upon diagram in section 2.1, first coin a term for the Origin-Len:ASCII-O= rigin pair (it is loosely referred to as set, which is easily confused wi= th Origin Set), for this email I=E2=80=99ll use the term Origin-Entry. Se= ction 2.1 would be changed to contain two clearly labelled diagrams: one = shall show the fields comprising an Origin-Entry, the other shall show th= e ORIGIN frame payload as an OPTIONAL sequence of Origin-Entries, with ca= rdinality of 0-*. 0 indicates an empty ORIGIN frame, which is implied by = the text in Appendix B - =E2=80=9Cinform the client that the connection i= s only to be used for the SNI-based origin, by sending an empty ORIGIN fr= ame.=E2=80=9D. -- = You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/368= ----==_mimepart_596dfeb0f0b5e_c3403fda8e3b3c30199450 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

From Lucas:

I naively assumed the ORIGIN frame was very similar to the ALTSVC fram= e, I missed out on the repetition element. I think it would help to impro= ve upon diagram in section 2.1, first coin a term for the Origin-Len:ASCI= I-Origin pair (it is loosely referred to as set, which is easily confused= with Origin Set), for this email I=E2=80=99ll use the term Origin-Entry.= Section 2.1 would be changed to contain two clearly labelled diagrams: o= ne shall show the fields comprising an Origin-Entry, the other shall show= the ORIGIN frame payload as an OPTIONAL sequence of Origin-Entries, with= cardinality of 0-*. 0 indicates an empty ORIGIN frame, which is implied = by the text in Appendix B - =E2=80=9Cinform the client that the connectio= n is only to be used for the SNI-based origin, by sending an empty ORIGIN= frame.=E2=80=9D.

&m= dash;
You are receiving this because you are subscribed to this thre= ad.
Reply to this email directly, view it on GitHub, or mute the thread.3D""

= ----==_mimepart_596dfeb0f0b5e_c3403fda8e3b3c30199450-- From nobody Tue Jul 18 05:28:24 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.382 X-Spam-Level: X-Spam-Status: No, score=-5.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Tue, 18 Jul 2017 05:28:21 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500380901; bh=HFsX4zCyb1OFnv3Txk5oJuWgr4925Eo/sQb/vZQmgf0=; h=From:Reply-To:To:Cc:Subject:List-ID:List-Archive:List-Post: List-Unsubscribe:From; b=StyjVjTEHPq3tHYepNFeL4rKSLxiqbY+7K12/nfxIng4z85OBiURhH3DCMIky0O+1 tLCF2Pv/uVpx9sMpNxWvw23Xufbg69JMQE2tYKixhM8i1jqXPGfgjvJQlePgQi8sqC mOwpFWd13fM4Uoap8CPsZGjfuPNptj5B/u9J0CXw= To: httpwg/http-extensions Cc: Subscribed Subject: [httpwg/http-extensions] Expectations of Origin Set Size (#369) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596dfee59c8bd_70d3fa764d6fc2c225cf"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 18 Jul 2017 12:28:24 -0000 ----==_mimepart_596dfee59c8bd_70d3fa764d6fc2c225cf Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable >From Lucas: If my interpretation of the specification is correct, the Origin Set is c= urrently unbounded. While the size of an individual H2 frame is bounded a= nd negotiated, the Origin set can seemingly be added to ad nauseam. Even = in the default size case, for a short ASCII-Origin such as http://dk, if = might be possible to create an Origin set with ~1500 entries. I like the = fact that ORIGIN frame extension doesn=E2=80=99t need any negotiation, so= perhaps some guidance for client-side implementations would help e.g. be= aware of the Origin Set size and be prepared to close the connection if = you=E2=80=99re getting unhappy. -- = You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/369= ----==_mimepart_596dfee59c8bd_70d3fa764d6fc2c225cf Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

From Lucas:

If my interpretation of the specification is correct, the Origin Set i= s currently unbounded. While the size of an individual H2 frame is bounde= d and negotiated, the Origin set can seemingly be added to ad nauseam. Ev= en in the default size case, for a short ASCII-Origin such as http://dk, if might be possible to create an Origin set wi= th ~1500 entries. I like the fact that ORIGIN frame extension doesn=E2=80= =99t need any negotiation, so perhaps some guidance for client-side imple= mentations would help e.g. be aware of the Origin Set size and be prepare= d to close the connection if you=E2=80=99re getting unhappy.

&m= dash;
You are receiving this because you are subscribed to this thre= ad.
Reply to this email directly, view it on GitHub, or mute the thread.3D""

= ----==_mimepart_596dff05c240d_1ddf3f8c7d749c3c16489c-- From nobody Tue Jul 18 12:36:49 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.383 X-Spam-Level: X-Spam-Status: No, score=-0.383 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=MrHwS/SViRC7fnMuQlQHWc4SdUA=; b=Sq9td5GEfcVoQmgr B2eaApaaxqXn1b9a7jw1ZxnLZ4AW2/Ouv3da2RtZk07rhOA00e+v71E1fvvods8/ RY+H0nxmMnD9B2ExClFOqJbysspZVt0RUwarriF+4t5/tkG8Alkw3t5223luy/kU nBwCAv1FnAczxCVCbsAg/WzNMDk= Date: Tue, 18 Jul 2017 19:36:42 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed Subject: [httpwg/http-extensions] multiple 103s are cumulating or overwriting headers? (#371) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596e634954c23_52cb3f8363797c341140d0"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 18 Jul 2017 19:36:47 -0000 ----==_mimepart_596e634954c23_52cb3f8363797c341140d0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit In section 2. "103 Early Hints" the last paragraph describes that 103 can be send multiple time. The given example reads as if a server may correct its previous 103 that is made from a cached resource. So the following 103 are correcting the older ones, they are only adding headers to the previous ones or are they replacing them completely? Maybe sentence clarifying this would be good. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/371 ----==_mimepart_596e634954c23_52cb3f8363797c341140d0 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

In section 2. "103 Early Hints" the last paragraph describes that 103 can be send multiple time. The given example reads as if a server may correct its previous 103 that is made from a cached resource. So the following 103 are correcting the older ones, they are only adding headers to the previous ones or are they replacing them completely? Maybe sentence clarifying this would be good.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596e634954c23_52cb3f8363797c341140d0-- From nobody Wed Jul 19 05:53:08 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.596 X-Spam-Level: X-Spam-Status: No, score=-0.596 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=ATdEBWW7Wk1SVqxsS74n2VUjvBg=; b=A214H6BH8dDLrJjc WVrT86y/iSwprs/pIWfETHZavT/Ww7Iol5GwPvgQxKQfgQtynMXF27aXbNkLbH7z lvkDnUjrCjQYNGHLZ+km6/4PAODdyjyNxrDpESU9vEdx2tJXXmbyIaDZ90sAS4U6 1XxOY5LPvfuGDSfEeRbYwKu7wY8= Date: Wed, 19 Jul 2017 12:52:58 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Form-encode Expect-CT report bodies? (#356) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596f562a74916_67323fd02c131c30630c0"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Jul 2017 12:53:02 -0000 ----==_mimepart_596f562a74916_67323fd02c131c30630c0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Moving discussion over to Fetch (https://github.com/whatwg/fetch/issues/567), will circle back here if it turns out there's something we should do in Expect-CT specifically. cc @martinthomson -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/356#issuecomment-316376170 ----==_mimepart_596f562a74916_67323fd02c131c30630c0 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Moving discussion over to Fetch (whatwg/fetch#567), will circle back here if it turns out there's something we should do in Expect-CT specifically. cc @martinthomson


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596f562a74916_67323fd02c131c30630c0-- From nobody Wed Jul 19 05:53:16 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.402 X-Spam-Level: X-Spam-Status: No, score=-0.402 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=lfG47mwTRpYmhbCHmuTmdR0mHvc=; b=sQVSgdIk4atVWdE+ SYZ12Llw3ktkzl/i6mh7eRHc4AEziUEu1UaGYliikEzD0WGkvDEpXV4QtMmkYUOS fFKPpf7tjCQE/f0JrG9UopoI9rMiwdjI1ZjHGGLb7PShntDsvBneuAWYWbcsu4PR 2z5WYyXHhBzC0VlCQi3GJmtqxHU= Date: Wed, 19 Jul 2017 12:52:59 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Form-encode Expect-CT report bodies? (#356) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596f562a7097e_70563fd02c131c301659ed"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Jul 2017 12:53:09 -0000 ----==_mimepart_596f562a7097e_70563fd02c131c301659ed Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #356. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/356#event-1170168934 ----==_mimepart_596f562a7097e_70563fd02c131c301659ed Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #356.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596f562a7097e_70563fd02c131c301659ed-- From nobody Wed Jul 19 07:06:57 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.596 X-Spam-Level: X-Spam-Status: No, score=-0.596 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=Tbpih1rzhh6Uba3ZEt6XNvEzTxA=; b=YRMXpo0XLaZ5orUi IM5U9TVvS+259awGRm85zRCoelZbBlMs3JRCId4GPNT5SGeRcQrLLlu+10E/tDw4 w694cnt8ZnuTzuWr4maBrEWseMVuL9wkDUHD1m2vzsj2ffMk/sdUIa0bl4FpBfvF ba/aPWnLHgBEJoO1achcTpj5emw= Date: Wed, 19 Jul 2017 14:06:51 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Form-encode Expect-CT report bodies? (#356) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596f668caed6b_8f53fddc3f39c348952b"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Jul 2017 14:06:56 -0000 ----==_mimepart_596f668caed6b_8f53fddc3f39c348952b Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @estark37, I don't want to create a false impression that there is no issue remaining. Is your intent to track the issue we discussed in some other way? As we discussed, I think that the requesting origin for the request is the origin of the response that contained the Expect-CT header field. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/356#issuecomment-316397412 ----==_mimepart_596f668caed6b_8f53fddc3f39c348952b Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

@estark37= , I don't want to create a false impression that there is no issue rema= ining. Is your intent to track the issue we discussed in some other way?

As we discussed, I think that the requesting origin for the request is t= he origin of the response that contained the Expect-CT header field.

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyCfvikEziYR= RQL0lycIAdKOCMlEqks5sPgyMgaJpZM4Nqnfc">mute the thread.3D""

= ----==_mimepart_596f668caed6b_8f53fddc3f39c348952b-- From nobody Wed Jul 19 07:19:07 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.115 X-Spam-Level: X-Spam-Status: No, score=-5.115 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Wed, 19 Jul 2017 07:18:55 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500473935; bh=DXSFGr96Iz3yBFC1cZg90INO55G5+Iuty1WUvUmoqRs=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=HZP14eIjrBPCDJYVv8vFW0lMkUCju9lr3QvCyL8eouBZEp4hN2VxdEDPYcafDL+AM O4Nm+PA4P+ejhbBeUuMnwPEkv2Es19kTRBaZElyjC6YCDno8qztuI+66BCmCEtngAx +zSk7inf/FF4CGKfAf0Ae/XTUJ2DF7lEmpYoWLRM= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Form-encode Expect-CT report bodies? (#356) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596f6a4f94d18_413b3fe21a38fc349517a"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Jul 2017 14:19:00 -0000 ----==_mimepart_596f6a4f94d18_413b3fe21a38fc349517a Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @martinthomson I thought your suggestion was to discuss with Fetch how to handle these requests? I'm fine with using the Expect-CT origin as the Origin for the preflight, but I'm still not sure that the Expect-CT spec is the right place to say that, as it doesn't make sense for non-browser clients. (I think it belongs better in Fetch.) -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/356#issuecomment-316402359 ----==_mimepart_596f6a4f94d18_413b3fe21a38fc349517a Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

@m= artinthomson I thought your suggestion was to discuss with Fetch how = to handle these requests?

I'm fine with using the Expect-CT origin as the Origin for the preflig= ht, but I'm still not sure that the Expect-CT spec is the right place to = say that, as it doesn't make sense for non-browser clients. (I think it b= elongs better in Fetch.)

&m= dash;
You are receiving this because you are subscribed to this thre= ad.
Reply to this email directly, view it on GitHub, or mute the thread.

=
= ----==_mimepart_596f6a4f94d18_413b3fe21a38fc349517a-- From nobody Wed Jul 19 07:19:13 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.181 X-Spam-Level: X-Spam-Status: No, score=-8.181 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Wed, 19 Jul 2017 07:18:56 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500473936; bh=A4qlrHLg6SWesAv+ej0WP8eJT22elwV4+NvTkqtOWUI=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=styQD1Z5ZZyWMdd7ZUC50I2RQ4bUGAinQGUeR4j6DNz8/2RrA299AnD5Q3IzzJtdO GDT9gTcyRwlRkVg3SK3t+pxhsZ1FjIs26313Es1YI7wiyeXMlaE2fU6GoojMdWAXrV snkvBLDFKaNGrDmcNz97I9XnFK35UksXHFPLaAsk= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Form-encode Expect-CT report bodies? (#356) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596f6a503292d_56983fefa3605c34801d7"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Jul 2017 14:19:01 -0000 ----==_mimepart_596f6a503292d_56983fefa3605c34801d7 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Reopened #356. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/356#event-1170328769 ----==_mimepart_596f6a503292d_56983fefa3605c34801d7 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Reopened #356.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_596f6a503292d_56983fefa3605c34801d7-- From nobody Wed Jul 19 07:32:38 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.382 X-Spam-Level: X-Spam-Status: No, score=-0.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=uHSHknN6xRUAaxwyyLLC4fbEEnM=; b=NweNfMXpFxVO1bhP e2B443abLvkIBunJtVx9yxlwFn8TTj860e8xtjkiDOl5+PLWDum4Yf7YjuNZu8NJ KVVhma6Tnr0AW3stuTgp4kGEf1lEozlLA0AR+a3gbTTsjkiJMTPAMpunOH8ZwGuA y2U32XUkQU3UthhbB2OG6P7Es0M= Date: Wed, 19 Jul 2017 14:32:35 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Form-encode Expect-CT report bodies? (#356) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596f6d8313346_67823febae7c3c2c115553"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Jul 2017 14:32:38 -0000 ----==_mimepart_596f6d8313346_67823febae7c3c2c115553 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit OK, that sounds good. My suggestion is to keep this open until we have greater clarity about how this is captured, even if that means closing this with no action because Fetch is covering it. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/356#issuecomment-316406555 ----==_mimepart_596f6d8313346_67823febae7c3c2c115553 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

OK, that sounds good. My suggestion is to keep this open until we have greater clarity about how this is captured, even if that means closing this with no action because Fetch is covering it.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

= ----==_mimepart_596f7ebf28860_5d463fea0cd75c2c1000ee-- From nobody Wed Jul 19 09:14:59 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -2.72 X-Spam-Level: X-Spam-Status: No, score=-2.72 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=41UHfckfWINAeWwBYRpytvu0f/g=; b=rq3KCN7lPnPDCqGv hHe+BVsqVAhZ3dFEk3im54y9j09s0QChqnS6ptXLcmaKOuKqvbCFN3Wp1ba8khZB hoa/10WVx/zDaAU/56KryD3v4PK9vPodUnYerXcVdDUZ9zyEAM/EjYNhPrpKXCsH 3lgVcmB7SlX5b8G3jE6sxSIGs4Q= Date: Wed, 19 Jul 2017 16:14:32 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Accept-CH-Lifetime privacy concerns (#372) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_596f82b2406de_5e593fbc57ffbc2c20865f"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Jul 2017 16:14:58 -0000 ----==_mimepart_596f82b2406de_5e593fbc57ffbc2c20865f Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit > The introduction of Accept-CH-Lifetime will extend this problem to all resources on a given origin -- if one page sets the header, then subresource requests from all pages in that origin will start carrying hint information. IIUC, this is not correct. If the origin includes `Accept-CH-Lifetime` header, then the user agent is expected to send the client hints for requests to only that origin. > Similarly, hints should probably also be stripped on HTTPS -> HTTP transitions. The Chromium implementation (currently underway) processes `Accept-CH-Lifetime` header from only HTTPS origins. So, the client hints sent because the user agent received `Accept-CH-Lifetime` in the past would be sent to only HTTPS origins. Quoting the spec: > Implementers ought to provide mechanisms and policies to control how and when such hints are advertised. cc'ing @igrigorik to comment on if any spec changes are needed here to make this more explicit. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/372#issuecomment-316434821 ----==_mimepart_596f82b2406de_5e593fbc57ffbc2c20865f Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

The introduction of Accept-CH-Lifetime will extend this problem to all r= esources on a given origin -- if one page sets the header, then subresource= requests from all pages in that origin will start carrying hint informatio= n.

IIUC, this is not correct. If the origin includes Accept-CH-Lifeti= me header, then the user agent is expected to send the client hints = for requests to only that origin.

Similarly, hints should probably also be stripped on HTTPS -> HTTP tr= ansitions.

The Chromium implementation (currently underway) processes Accept-= CH-Lifetime header from only HTTPS origins. So, the client hints sen= t because the user agent received Accept-CH-Lifetime in the pa= st would be sent to only HTTPS origins. Quoting the spec:

Implementers ought to provide mechanisms and policies to control how
and when such hints are advertised.

cc'ing @= igrigorik to comment on if any spec changes are needed here to make thi= s more explicit.

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyJFRZt-iw0N= dFniewGcBeCU-qeRzks5sPiiygaJpZM4Oc7TI">mute the thread.3D""

= ----==_mimepart_596fbc0b61e07_14643f8718d03c3c46721-- From nobody Wed Jul 19 20:29:48 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -2.021 X-Spam-Level: X-Spam-Status: No, score=-2.021 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=ixfiIJX7rdqNWCHzEVEy3ns+lYg=; b=oauO+8ZUgG7bNNDJ karMkClGWQnlUpe4CDi6tMw1fqCX4ytkKJUerKsfE1wVJltf1YHU/wqFhirUeDB9 gCMs5Qq2zGFOBruUfPViLpUTUwlDlxSYRkjf1b+PQ89mlGRQPL6KZBgwcPTteo64 dtPHK7mdrjbotpR5rthuTn6vvzY= Date: Thu, 20 Jul 2017 03:29:44 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Accept-CH-Lifetime privacy concerns (#372) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597023a84efcb_1f99a3fdd546efc3c123683"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 20 Jul 2017 03:29:47 -0000 ----==_mimepart_597023a84efcb_1f99a3fdd546efc3c123683 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable @arturjanc thanks for the great feedback. Let me try to unpack... Prior to introduction of `Accept-CH-Lifetime` (ACL) =E2=80=94 which is very= recent =E2=80=94 there was no mechanism in place for an origin to persist = a preference for hints across independent requests. As a result, navigation= requests did not get any hints and only subrequests of the "opted-in docum= ent" were eligible. The extra complication here is that the initial set of = core use cases (image optimization) frequently relies on use of CDN's and t= hird-party services+origins, which means that prior to ACL there was no way= for those origins to enable CH hints, since page origin !=3D resource orig= in. As a result, the decision was to extend Accept-CH opt-in to all resourc= es fetched by the page. Now that we have ACL, it may be possible to revisit this setup. In particul= ar, if we scope ACL to per-origin, then both the page origin and resource o= rigin can advertise support separately and these preferences will be persis= ted across requests. In fact, I suspect that this is what will happen anywa= y, because for cases like image serving CDNs will advertise support for hin= ts on their own origins, such that any site relying on their service can be= nefit by default. @yoavweiss wdyt? --- > What about HTTPS pages which have HTTP subresources? The behavior I curre= ntly see for Accept-CH is that the HTTP subresource requests have client hi= nts (but no Referer); > ... > Obeying Referrer Policy and omitting hints if the referring page attempts= to restrict data which is sent in the Referer header. Similarly, hints sho= uld probably also be stripped on HTTPS -> HTTP transitions. I think this would naturally fall out of the origin-scoped model? As in, if= opt-in is scoped to HTTPS then we wouldn't send hints to HTTP, unless the = HTTP origin also explicitly opted-in.=20 Re, Referer: "I have third party resources on my site, which may have hint= s enabled, and I want to strip those alongside referrers", is that the use = case? If so, that seems legitimate, but using Referer does feel a little ac= tion-at-a-distance to me. As in, I wouldn't expect Referrer to control hint= s? That said, I don't have a better suggestion either. @mikewest wdyt? > A related issue is that based on the sets of headers sent in such subreso= urce requests, the subresource owner might be able to identify the referrin= g site even if it sets a Referrer Policy to prevent disclosing its URL or o= rigin. For example, requests from a large site which sets Referrer-Policy: = no-referrer; Accept-CH: DPR will be distinguishable from requests from site= s with Accept-CH: DPR, Viewport-Width and from those without client hints. = Depending on the chosen set of hints this can in practice uniquely identify= the origin visited by the user. Good points, we should flag this in the privacy & security section. --=20 You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/372#issuecomment-316586505= ----==_mimepart_597023a84efcb_1f99a3fdd546efc3c123683 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

@arturja= nc thanks for the great feedback. Let me try to unpack...

Prior to introduction of Accept-CH-Lifetime (ACL) =E2=80=94= which is very recent =E2=80=94 there was no mechanism in place for an orig= in to persist a preference for hints across independent requests. As a resu= lt, navigation requests did not get any hints and only subrequests of the "= opted-in document" were eligible. The extra complication here is that the i= nitial set of core use cases (image optimization) frequently relies on use = of CDN's and third-party services+origins, which means that prior to ACL th= ere was no way for those origins to enable CH hints, since page origin !=3D= resource origin. As a result, the decision was to extend Accept-CH opt-in = to all resources fetched by the page.

Now that we have ACL, it may be possible to revisit this setup. In parti= cular, if we scope ACL to per-origin, then both the page origin and resourc= e origin can advertise support separately and these preferences will be per= sisted across requests. In fact, I suspect that this is what will happen an= yway, because for cases like image serving CDNs will advertise support for = hints on their own origins, such that any site relying on their service can= benefit by default.

@yoavwei= ss wdyt?


What about HTTPS pages which have HTTP subresources? The behavior I curr= ently see for Accept-CH is that the HTTP subresource requests have client h= ints (but no Referer);
...
Obeying Referrer Policy and omitting hints if the referring page attempts t= o restrict data which is sent in the Referer header. Similarly, hints shoul= d probably also be stripped on HTTPS -> HTTP transitions.

I think this would naturally fall out of the origin-scoped model? As in,= if opt-in is scoped to HTTPS then we wouldn't send hints to HTTP, unless t= he HTTP origin also explicitly opted-in.

Re, Referer: "I have third party resources on my site, which may have h= ints enabled, and I want to strip those alongside referrers", is that the u= se case? If so, that seems legitimate, but using Referer does feel a little= action-at-a-distance to me. As in, I wouldn't expect Referrer to control h= ints? That said, I don't have a better suggestion either. @mikewest wdyt?

A related issue is that based on the sets of headers sent in such subres= ource requests, the subresource owner might be able to identify the referri= ng site even if it sets a Referrer Policy to prevent disclosing its URL or = origin. For example, requests from a large site which sets Referrer-Policy:= no-referrer; Accept-CH: DPR will be distinguishable from requests from sit= es with Accept-CH: DPR, Viewport-Width and from those without client hints.= Depending on the chosen set of hints this can in practice uniquely identif= y the origin visited by the user.

Good points, we should flag this in the privacy & security section.<= /p>

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyPOelwjCwst= hC90WOdtlCF6upi3Qks5sPsmogaJpZM4Oc7TI">mute the thread.3D""

= ----==_mimepart_597023a84efcb_1f99a3fdd546efc3c123683-- From nobody Thu Jul 20 03:47:17 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -2.721 X-Spam-Level: X-Spam-Status: No, score=-2.721 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=1bmM3th25BQhAYayqK8cZZKNDeE=; b=SLffJMVJCekmQfy8 A+gobKH1vdAyXcH3mDh5zE+y6pS7SDpwmHQjmGGpnfIrHj/rdJPZbCbb/eEoMr3M Qj676DDeapXdhrhFoE4oxvSkQq17dMJ1x5vbMEW0g2x8clzXXdhY40MZSUHOCSgN +uiSIqWQ8eu2OMmR5QfI6XaePuw= Date: Thu, 20 Jul 2017 10:47:06 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Accept-CH-Lifetime privacy concerns (#372) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_59708a2998e4d_20e943fd96f3dbc3c2160ae"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 20 Jul 2017 10:47:16 -0000 ----==_mimepart_59708a2998e4d_20e943fd96f3dbc3c2160ae Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit > Now that we have ACL, it may be possible to revisit this setup. In particular, if we scope ACL to per-origin, then both the page origin and resource origin can advertise support separately and these preferences will be persisted across requests. This seems like a better model than the status quo because it limits the sending of hints to origins which opt into receiving them. However, it still has the issue of revealing new information to providers of third-party subresources which they can't obtain now. This seems fine to do with opt-in from the first party (which can already get the Viewport-Width, etc via client-side scripts and then provide it to the CDN in the URL), but seems less great if the CDN can decide to always get hints in all requests, because of the passive fingerprinting potential. What do you think of double-keying the hints on both the first- and third-party? That is, if you set `Accept-CH(-Lifetime)`: - Requests for same-origin subresources will carry client hints (up until the max-age if you specify the lifetime). - Requests for non-same-origin subresources will not carry client hints if the other origin doesn't set `Accept-CH-Lifetime`. - If you load third-party resources from an origin which sets `Accept-CH-Lifetime`, requests from your origin to the third party will carry client hints. - Requests from other origins (which don't set `Accept-CH`) to the third party will not carry hints. I realize this reduces the "on by default" benefit you mentioned, but it seems like a relatively simple opt-in for the first party (which is already a necessary condition in `Accept-CH`) and it mitigates the risk of enabling passive tracking of users based on client hints, which I assume will evolve to expose more interesting data. As you mentioned above, this would also make the Referrer discussion moot (and I agree that controlling client hints via Referrer Policy seems awkward). -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/372#issuecomment-316667172 ----==_mimepart_59708a2998e4d_20e943fd96f3dbc3c2160ae Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

Now that we have ACL, it may be possible to revisit this setup. In parti= cular, if we scope ACL to per-origin, then both the page origin and resourc= e origin can advertise support separately and these preferences will be per= sisted across requests.

This seems like a better model than the status quo because it limits the= sending of hints to origins which opt into receiving them. However, it sti= ll has the issue of revealing new information to providers of third-party s= ubresources which they can't obtain now. This seems fine to do with opt-in = from the first party (which can already get the Viewport-Width, etc via cli= ent-side scripts and then provide it to the CDN in the URL), but seems less= great if the CDN can decide to always get hints in all requests, because o= f the passive fingerprinting potential.

What do you think of double-keying the hints on both the first- and thir= d-party? That is, if you set Accept-CH(-Lifetime):

  • Requests for same-origin subresources will carry client hints (up until= the max-age if you specify the lifetime).
  • Requests for non-same-origin subresources will not carry client hints i= f the other origin doesn't set Accept-CH-Lifetime.
  • If you load third-party resources from an origin which sets Accep= t-CH-Lifetime, requests from your origin to the third party will car= ry client hints.
  • Requests from other origins (which don't set Accept-CH) to= the third party will not carry hints.

I realize this reduces the "on by default" benefit you mentioned, but it= seems like a relatively simple opt-in for the first party (which is alread= y a necessary condition in Accept-CH) and it mitigates the ris= k of enabling passive tracking of users based on client hints, which I assu= me will evolve to expose more interesting data. As you mentioned above, thi= s would also make the Referrer discussion moot (and I agree that controllin= g client hints via Referrer Policy seems awkward).

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyNakbQDbng5= 8g9B8Jg9UiyOF0oXiks5sPzApgaJpZM4Oc7TI">mute the thread.3D""

= ----==_mimepart_59708a2998e4d_20e943fd96f3dbc3c2160ae-- From nobody Fri Jul 21 07:54:15 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -2.02 X-Spam-Level: X-Spam-Status: No, score=-2.02 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=YK+xXuKoB75IeaJcwhZO2D6k90g=; b=cC/m9f2BdhsnVjmE sJygUlLQItRVkOu/7+EoiDL9TH+jSgUHXznAZpQnaCB9wcTfyjoRWjOaUHKpZ24o tg3hQ0z8I29KlNM34Bm8IXuvK89WVLkpP8/UQ3vrw9pw2qg4cZphV/sD8EtNoy5Q w6LLH1Tt0Hn81cHQ7DuNT7vs9/M= Date: Fri, 21 Jul 2017 14:54:09 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Geolocation Header (#364) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597215912d9fe_26c653fb8d26b7c343963f"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 14:54:14 -0000 ----==_mimepart_597215912d9fe_26c653fb8d26b7c343963f Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit > One major difference between this and the other CH headers is that this header should only be sent to the first party (or only to hosts which have permission to view geolocation data, so to third parties that got such permissions before). See https://github.com/httpwg/http-extensions/issues/372 for discussions related to that. I think this example is highlighting the need for origin-scoped hints, which I think we can do with ACH. > So on my side, if others think CH is the right approach for this, then for consistency and simplicity I'd be happy to follow that path and start a draft, on top of CH. Happy to hear other opinions :) I think CH is the right fit. For a hot-off-the-press example, take a look at the [Device Memory i2s on blink-dev](https://groups.google.com/a/chromium.org/forum/#!msg/blink-dev/8qlTjzRY9Mc/BYCuqWJXBwAJ).. Assuming we can drop the prompt trigger and path requirements, you can just follow that template. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/364#issuecomment-317023050 ----==_mimepart_597215912d9fe_26c653fb8d26b7c343963f Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

One major difference between this and the other CH headers is that this = header should only be sent to the first party (or only to hosts which have = permission to view geolocation data, so to third parties that got such perm= issions before).

See #372 f= or discussions related to that. I think this example is highlighting the ne= ed for origin-scoped hints, which I think we can do with ACH.

So on my side, if others think CH is the right approach for this, then f= or consistency and simplicity I'd be happy to follow that path and start a = draft, on top of CH. Happy to hear other opinions :)

I think CH is the right fit. For a hot-off-the-press example, take a loo= k at the Device Memory i2s on blink-dev.. Assu= ming we can drop the prompt trigger and path requirements, you can just fol= low that template.

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyNS4ZlwVgDK= WTBecHKsdemMEg0JKks5sQLuRgaJpZM4OJSIe">mute the thread.3D""

= ----==_mimepart_597215912d9fe_26c653fb8d26b7c343963f-- From nobody Fri Jul 21 07:56:03 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -7.681 X-Spam-Level: X-Spam-Status: No, score=-7.681 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Fri, 21 Jul 2017 07:55:58 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500648958; bh=Idvc7mKEJvOdEKLuGAGGL29GIP1niz4gxEsuULE0q48=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=UGiySXwy0FAjTVkpgqgFvz+Fftt4HgPtfUdyr2wQVDwOMK/7164k9WoP7MF0NHsj1 5Fit1Ha3V/9Cv0jxC6pfvKLayNnmEfj16KBgL6S66qcptzslC8jgkt76ljS/o8ouez ryuh6pXzzrjSjHU8lSN0mH39RD9xOcnudfGsacfE= To: httpwg/http-extensions Cc: Push In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Address client-hints-04 feedback (#361) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597215fee9d00_99183fc121603c3c2113fd"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 14:56:01 -0000 ----==_mimepart_597215fee9d00_99183fc121603c3c2113fd Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @igrigorik pushed 1 commit. b742630 fix Key reference in appendix -- You are receiving this because you are subscribed to this thread. View it on GitHub: https://github.com/httpwg/http-extensions/pull/361/files/19e5cb07e2d9e075ce83fc4a386e7ae2ffd41461..b742630a1f109146b4bab553dadb7ae63b1e34ce ----==_mimepart_597215fee9d00_99183fc121603c3c2113fd Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@igrigorik pushed 1 commit.

  • b742630 fix Key reference in appendix


You are receiving this because you are subscribed to this thread.
View it on GitHub or mute the thread.

----==_mimepart_597215fee9d00_99183fc121603c3c2113fd-- From nobody Fri Jul 21 08:04:27 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.381 X-Spam-Level: X-Spam-Status: No, score=-5.381 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Fri, 21 Jul 2017 08:04:23 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500649463; bh=8ggOj7CWCzKz8WkQEH7hxxZZX1GLSg+gVFewdRydkqM=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=wYtkh7O/Iu2AiwZH3AgUL5LflmsqvkgU4XrqhX86RLhIiQkMPsBvdMOpixiXu8EZR rohi6kIGlhEZ8fuwCEdPMC85Vhg7wGxXwk3anLkvyVPJs++F7r1H5RNbRAg8hHJjYC NYcCEqovT/GmU1nuXkEaMlNBim+ngWN5FIMW1Ros= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Address client-hints-04 feedback (#361) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597217f769c65_5b6d3fbb9bf69c3075042"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 15:04:26 -0000 ----==_mimepart_597217f769c65_5b6d3fbb9bf69c3075042 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Merged #361. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/361#event-1174041347 ----==_mimepart_597217f769c65_5b6d3fbb9bf69c3075042 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Merged #361.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597217f769c65_5b6d3fbb9bf69c3075042-- From nobody Fri Jul 21 08:05:18 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.454 X-Spam-Level: X-Spam-Status: No, score=-0.454 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=de+NQdWoI0Nt2OQFpeojxpnmFD0=; b=hfWtUAusMtlypzQo m1XGAbcDWCVQPK9nkhEbNiRV+9qzx+bMKOaWl5kx2pfqOGUGk3lYFOMugfGvQ8mI iDkQ3IvFXUvLbk4hJoQrT6j+xrJW4ZFCxakJpAKvi+Ut71ZclYMith3hQvHVBtfH ytffnC0Rrv8qpHsi7x6h/hh41ww= Date: Fri, 21 Jul 2017 15:05:02 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Address client-hints-04 feedback (#361) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_5972181b5eaf3_98f53fc121603c3c311316"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 15:05:17 -0000 ----==_mimepart_5972181b5eaf3_98f53fc121603c3c311316 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @reschke merging. If you have any followup feedback, we can open a new issue. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/361#issuecomment-317026075 ----==_mimepart_5972181b5eaf3_98f53fc121603c3c311316 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@reschke merging. If you have any followup feedback, we can open a new issue.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_5972181b5eaf3_98f53fc121603c3c311316-- From nobody Fri Jul 21 08:05:30 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.402 X-Spam-Level: X-Spam-Status: No, score=-0.402 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=8I6UUEZSHeIUXrNfZbZ0NnfTsjE=; b=Hx5JgtvVTa5mXhLP cr5r12dmKV1Fpblr5ijbiLTJz+K6zhN0lv6sFm9PnYi1fWlT5W4Nr1j9PUDQMbG1 J3Z7UicYNcoGzgjTjp0og/dV7NeDM2699M9+XzzAZ7gSufbOVCm7+oiOYHTwovg3 D4tBMwKDg5T2wVcipCBSAvgnSKg= Date: Fri, 21 Jul 2017 15:05:24 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Julian's CH feedback (#359) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_59721831958dc_36bb3f900a163c383309b2"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 15:05:29 -0000 ----==_mimepart_59721831958dc_36bb3f900a163c383309b2 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #359. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/359#event-1174043275 ----==_mimepart_59721831958dc_36bb3f900a163c383309b2 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #359.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_59721831958dc_36bb3f900a163c383309b2-- From nobody Fri Jul 21 08:05:37 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.182 X-Spam-Level: X-Spam-Status: No, score=-3.182 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=3fH+jWDTGH8m6+oqZRaqI4ROtcI=; b=NZ8W5w1M+/mOwLIc RuTnNLqGjAL5EGqcnXwjIVw89w5tj7MUh1bOEj86MsvHTSsywgCGDJPmzlypKTuM LP1IaVbVSJ5tNow7aa9lIJzybTQ5qXjksPyOXBNo8rJ55F+En76TdW8gWRb8YyQK F3l2FZ5C7QqhqBB8BlYosswe42E= Date: Fri, 21 Jul 2017 15:05:25 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Julian's CH feedback (#359) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_5972183166498_26ca93fb8d26b7c341168b0"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 15:05:32 -0000 ----==_mimepart_5972183166498_26ca93fb8d26b7c341168b0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Resolved via https://github.com/httpwg/http-extensions/pull/361. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/359#issuecomment-317026164 ----==_mimepart_5972183166498_26ca93fb8d26b7c341168b0 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Resolved via #361.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_5972183166498_26ca93fb8d26b7c341168b0-- From nobody Fri Jul 21 08:05:42 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -7.681 X-Spam-Level: X-Spam-Status: No, score=-7.681 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Fri, 21 Jul 2017 08:05:30 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500649530; bh=+mRYodWRRJg158plom1mYB/5xr409x93mL2anMUCMEA=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=0/B0FEcwTEIMCcOKXuE1YFax5Om22PDDi9PL4H0sOGUeTqHfLrSiXM05KQE+9m+Va dUhbvONdYLJeqWd6Vk6KnGAYFiPGWwRioOvGUgJZAlDpJmTtM35Rd3G0xjyzIx10Jt YH7NbAXf3rWou/zgM3y/vp5M2QX5BqVaooo37Xa0= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Header relationships, cardinality (#360) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_5972183a85a54_2583fd8c8617c3c2243f9"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 15:05:32 -0000 ----==_mimepart_5972183a85a54_2583fd8c8617c3c2243f9 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #360. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/360#event-1174043516 ----==_mimepart_5972183a85a54_2583fd8c8617c3c2243f9 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #360.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_5972183a85a54_2583fd8c8617c3c2243f9-- From nobody Fri Jul 21 08:05:45 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -7.681 X-Spam-Level: X-Spam-Status: No, score=-7.681 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Fri, 21 Jul 2017 08:05:30 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500649530; bh=ica/dO7+NzmOmGpm3+JzCJyn4Rt78GzJQPt8EhFDvW4=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=zhbKBfdWdpkJ7OttM44lWH8lcd7zdA5FiSN231pUPuFVxrJYI8PEpy+3UkN54df4H MBR3vVnM3b4b9guIOnnuJrBhtvP0VH1zvL9rUTin+T8+gxiMNzYvX6JPR1wKc3+Neq koKZwP4qd2J0bX3JS2dXm76t4BD+489iEDDhr2ME= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Header relationships, cardinality (#360) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_5972183ae4058_49d03fce0a3c9c3c24566c"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 15:05:33 -0000 ----==_mimepart_5972183ae4058_49d03fce0a3c9c3c24566c Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Resolved via https://github.com/httpwg/http-extensions/pull/361. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/360#issuecomment-317026196 ----==_mimepart_5972183ae4058_49d03fce0a3c9c3c24566c Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Resolved via #361.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_5972183ae4058_49d03fce0a3c9c3c24566c-- From nobody Fri Jul 21 08:12:21 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -9.298 X-Spam-Level: X-Spam-Status: No, score=-9.298 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Fri, 21 Jul 2017 08:12:17 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500649937; bh=9wN8YvrH48L6d2Qh2pfn+97Z3JjU8IAQgvaIRgxlAO0=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=lkBtowG8+EBW6J7RZdtg5D7BiqGmbsydK4mk3RCZU44qzL6oJYfjqohgGVpPH0JJl 0M493gdYxGiHdCchIc9ceUn01C6Q4LEh9KOfqnMC44bcBPFgYZJgzxb4MQPcmyzCjn i7rttLxSBPNtp7i+Lba+35Gydz+GdDdz3isjj3H4= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Accept-CH-Lifetime privacy concerns (#372) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597219d173996_703e3ff4d30d3c2c794c1"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 15:12:20 -0000 ----==_mimepart_597219d173996_703e3ff4d30d3c2c794c1 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Would double-keying have material effect on this though? Yes, implementing it this way reduces passive fingerprinting, but only for the very first visit. Nothing prevents every 3P origin from advertising a blanket opt-in policy (in fact, I expect that's exactly how image CDN's will implement it), which will result in same exposure for any repeat visit. Also, as a side effect, double-keying would expose first vs repeat visit bit? I'm not ruling it out, but it's not clear to me that it would be a big win in this context? -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/372#issuecomment-317027949 ----==_mimepart_597219d173996_703e3ff4d30d3c2c794c1 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

Would double-keying have material effect on this though? Yes, implemen= ting it this way reduces passive fingerprinting, but only for the very fi= rst visit. Nothing prevents every 3P origin from advertising a blanket op= t-in policy (in fact, I expect that's exactly how image CDN's will implem= ent it), which will result in same exposure for any repeat visit. Also, a= s a side effect, double-keying would expose first vs repeat visit bit?

I'm not ruling it out, but it's not clear to me that it would be a big= win in this context?

&m= dash;
You are receiving this because you are subscribed to this thre= ad.
Reply to this email directly, view it on GitHub, or mute the thread.

=
= ----==_mimepart_597219d173996_703e3ff4d30d3c2c794c1-- From nobody Fri Jul 21 09:30:37 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -4.799 X-Spam-Level: X-Spam-Status: No, score=-4.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=Io/I4cbwymeQmyff2vKmapnBVTw=; b=NrGVTsL20HFWCXKT txx6x57ZhHoqMVmv8HDYYnzjM4jn9K2G6vaxqJWCgqF6SZdyW1g7Smo+n1QxTn45 ep35h79Nw66erWCwHAR0de/lmC6EmjXevNXDQhK+DR/hlBPBOXF01CFVR4/m+DYo LqbbdB9CGH+JCHZq7bSlE2WxwfA= Date: Fri, 21 Jul 2017 16:30:28 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed Subject: [httpwg/http-extensions] Scope Accept-CH opt-in to same origin (#373) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_59722c243776f_26473fd096e7dc30157226"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 16:30:35 -0000 ----==_mimepart_59722c243776f_26473fd096e7dc30157226 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit WIP, based on discussion in #372. You can view, comment on, or merge this pull request online at: https://github.com/httpwg/http-extensions/pull/373 -- Commit Summary -- * scope Accept-CH opt-in to same-origin * rework security considerations -- File Changes -- M draft-ietf-httpbis-client-hints.md (16) -- Patch Links -- https://github.com/httpwg/http-extensions/pull/373.patch https://github.com/httpwg/http-extensions/pull/373.diff -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/373 ----==_mimepart_59722c243776f_26473fd096e7dc30157226 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

WIP, based on discussion in #372.


You can view, comment on, or merge this pull request online at:

  https://github.com/httpwg/http-extensions/pull/373

Commit Summary

  • scope Accept-CH opt-in to same-origin
  • rework security considerations

File Changes

Patch Links:


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_59722c243776f_26473fd096e7dc30157226-- From nobody Fri Jul 21 09:31:24 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.882 X-Spam-Level: X-Spam-Status: No, score=-3.882 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=y03cTJpc+D5B1Xn4pf+ZNuRXlVQ=; b=tp7x5VV9FxxPydcr t50PPCcp2q6LR7JZeTrZJRSIV1PPh3tpJPqAomBrd2i83VeOUOLjDYzN2XzF0b9m nflcDYtZ2S9g8M31EU8JPqBvG0KD1AxK9pLm4zlHKwhAPipfLHfhV35B822iwHbG h7/SKlZDjBUv5S81f0tR8vlllLY= Date: Fri, 21 Jul 2017 16:31:10 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Accept-CH-Lifetime privacy concerns (#372) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_59722c4e5050f_4a2a3fa831fa9c2c196134"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 21 Jul 2017 16:31:22 -0000 ----==_mimepart_59722c4e5050f_4a2a3fa831fa9c2c196134 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @arturjanc started a branch @ https://github.com/httpwg/http-extensions/pull/373 - ptal. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/372#issuecomment-317047991 ----==_mimepart_59722c4e5050f_4a2a3fa831fa9c2c196134 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@arturjanc started a branch @ #373 - ptal.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_59722c4e5050f_4a2a3fa831fa9c2c196134-- From nobody Sat Jul 22 08:17:14 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -2.721 X-Spam-Level: X-Spam-Status: No, score=-2.721 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=z2oCe1kY/JM8zWGyUJNqa9/q4IM=; b=RP6tVB9Dxs0vLdHn LNdm/noT+kNOwX3iX07683ahvDvHtMl7q8G8tOscrCoKpuJsSYNFL7CdCO54Y/dB Loy/bs/3ZVzRwsMQVSii3AQZK5HXaEee0mlxC1jkN59Y/3M0Qu9Rs2xh0G+GmGx+ 3u3VP3p2c2TuECFfNMeDNuMpxu8= Date: Sat, 22 Jul 2017 15:17:09 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Scope Accept-CH opt-in to same origin (#373) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_59736c748f2d5_77663fb2f183dc3429884"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 22 Jul 2017 15:17:13 -0000 ----==_mimepart_59736c748f2d5_77663fb2f183dc3429884 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit arturjanc commented on this pull request. > @@ -257,11 +257,13 @@ The Content-DPR response header field indicates to the client that the server ha # Security Considerations -The request header fields defined in this specification expose information that is already available to Web applications in the browser runtime itself (e.g., using JavaScript and CSS). For example, the application can obtain viewport width, image display width, and device pixel ratio via JavaScript, or through the use of CSS media queries and unique resource URLs even if JavaScript is disabled. However, servers that gather this information through such mechanisms are typically observable (e.g., you can see that they're using JavaScript to gather it), whereas servers' use of the header fields introduced by this specification is not observable. Section 2.1 discusses potential mitigations. +The request header fields defined in this specification, and those that extend it, expose information about the user's environment to enable proactive content negotiation. Such information may reveal new information about the user and implementers ought to provide policies and mechanisms to control how and when such hints are advertised. I'm worried about this being a little vague. It seems that there would be a benefit to specifying the "policies and mechanisms" mentioned in this para because they might be crucial to ensuring the privacy properties of a given implementation. > -For example, sending Client Hints on all requests can make information about the user's environment available to origins that otherwise did not have access to this data, which may or may not be the desired outcome - e.g. this may enable an image optimization service to deliver a tailored asset, and it may reveal same information about the user to other origins that may not have had access to it before. Similarly, sending highly granular data, such as image and viewport width may help identify users across multiple requests. Restricting such field values to an enumerated range, where the user agent advertises a threshold value that is close but is not an exact representation of the current value, can help mitigate the risk of such fingerprinting. +The hint request headers ought not to provide new information that is otherwise not available to the application via HTML, CSS, or JavaScript. For example, this specification defines Viewport-Width, Width, and DPR header fields, all of which can be obtained via JavaScript, or through the use of CSS media queries and unique resource URLs even if JavaScript is disabled. I would make this stronger: 1. Hints shouldn't provide information that isn't available via the usual channels. 2. Hints sent for subresource requests shouldn't carry information not available to the provider of the subresource unless the first-party opts into sending hints (note that this, combined with the same-origin restriction, would likely suggest some form of double-keying) -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/373#pullrequestreview-51624553 ----==_mimepart_59736c748f2d5_77663fb2f183dc3429884 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@arturjanc commented on this pull request.


In draft-ietf-httpbis-client-hints.md:

> @@ -257,11 +257,13 @@ The Content-DPR response header field indicates to the client that the server ha
 
 # Security Considerations
 
-The request header fields defined in this specification expose information that is already available to Web applications in the browser runtime itself (e.g., using JavaScript and CSS). For example, the application can obtain viewport width, image display width, and device pixel ratio via JavaScript, or through the use of CSS media queries and unique resource URLs even if JavaScript is disabled. However, servers that gather this information through such mechanisms are typically observable (e.g., you can see that they're using JavaScript to gather it), whereas servers' use of the header fields introduced by this specification is not observable. Section 2.1 discusses potential mitigations.
+The request header fields defined in this specification, and those that extend it, expose information about the user's environment to enable proactive content negotiation. Such information may reveal new information about the user and implementers ought to provide policies and mechanisms to control how and when such hints are advertised.

I'm worried about this being a little vague. It seems that there would be a benefit to specifying the "policies and mechanisms" mentioned in this para because they might be crucial to ensuring the privacy properties of a given implementation.


In draft-ietf-httpbis-client-hints.md:

>  
-For example, sending Client Hints on all requests can make information about the user's environment available to origins that otherwise did not have access to this data, which may or may not be the desired outcome - e.g. this may enable an image optimization service to deliver a tailored asset, and it may reveal same information about the user to other origins that may not have had access to it before. Similarly, sending highly granular data, such as image and viewport width may help identify users across multiple requests. Restricting such field values to an enumerated range, where the user agent advertises a threshold value that is close but is not an exact representation of the current value, can help mitigate the risk of such fingerprinting.
+The hint request headers ought not to provide new information that is otherwise not available to the application via HTML, CSS, or JavaScript. For example, this specification defines Viewport-Width, Width, and DPR header fields, all of which can be obtained via JavaScript, or through the use of CSS media queries and unique resource URLs even if JavaScript is disabled.

I would make this stronger:

  1. Hints shouldn't provide information that isn't available via the usual channels.
  2. Hints sent for subresource requests shouldn't carry information not available to the provider of the subresource unless the first-party opts into sending hints (note that this, combined with the same-origin restriction, would likely suggest some form of double-keying)


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_59736c748f2d5_77663fb2f183dc3429884-- From nobody Sat Jul 22 08:19:23 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -7.02 X-Spam-Level: X-Spam-Status: No, score=-7.02 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sat, 22 Jul 2017 08:19:17 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1500736757; bh=/Z4WZhHmk8JQmr7nlOC6M5KG/FxxcEyn1vr287OloMo=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=zQicb24oxMR2W+ob4YZsCvAvaQ/PLc3HRHr36gEECI9/RzYe7AVbUvZIGT+rKprJd uibhmc9mIFA/FFI1elf7OQdM7z7yHDf+YC4rToF5FSH7rQhUzDgVtZB4pYVNjUxhpp KX23K+ELI4dE8vBZsbh2n7JK2k2E+gNizvqY9anM= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Accept-CH-Lifetime privacy concerns (#372) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_59736cf5e494e_e6e3f8cb375bc30149359"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 22 Jul 2017 15:19:20 -0000 ----==_mimepart_59736cf5e494e_e6e3f8cb375bc30149359 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Re: double-keying, the point is that if you're visiting a first party _without_ Accept-CH then the browser wouldn't send client hints to a CDN even if it sets ACL. Essentially, if you have a first party which wants to use client hints they can opt into them and then their non-same-origin subresources can gets hints if their providers also set ACL (which is fine because the first party could manually pass the hints in the URLs anyway). This prevents CDNs and other origins from which subresources are loaded from getting hints during the user's visit to non-cooperating sites, but should still offer the benefits you're looking for in cases where both parties opt in. I commented on https://github.com/httpwg/http-extensions/pull/373 -- it looks good to me in general, modulo the broader double-keying issue (which I believe is important). -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/372#issuecomment-317190397 ----==_mimepart_59736cf5e494e_e6e3f8cb375bc30149359 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

Re: double-keying, the point is that if you're visiting a first party = without Accept-CH then the browser wouldn't send client hints to= a CDN even if it sets ACL. Essentially, if you have a first party which = wants to use client hints they can opt into them and then their non-same-= origin subresources can gets hints if their providers also set ACL (which= is fine because the first party could manually pass the hints in the URL= s anyway). This prevents CDNs and other origins from which subresources a= re loaded from getting hints during the user's visit to non-cooperating s= ites, but should still offer the benefits you're looking for in cases whe= re both parties opt in.

I commented on #373 -- it looks good to me in general, modulo the broader dou= ble-keying issue (which I believe is important).

&m= dash;
You are receiving this because you are subscribed to this thre= ad.
Reply to this email directly, view it on GitHub, or mute the thread.

=
= ----==_mimepart_59736cf5e494e_e6e3f8cb375bc30149359-- From nobody Sat Jul 22 08:33:36 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -1.103 X-Spam-Level: X-Spam-Status: No, score=-1.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=SCTpBISCYb76rf+DLefxyhAsuIk=; b=fnOo/LAtkvUIofqp NpZ3o7h1kQD+KU9siYuM+x8hJIDx9ZLOclS/YUGpKCO4EXapaEDUduTT8IjW0xbJ QoDY48fyZzGo5gk75Q/Vj3WWSFMfrCro6hVojZxkvsPmP+kgvXjuQFf9nXYoBSL0 8Uc+cvwyAHolatqbx21PrZI09nc= Date: Sat, 22 Jul 2017 15:33:33 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Accept-CH-Lifetime privacy concerns (#372) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_5973704d17b45_b6543f9f1c1d7c3476314"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 22 Jul 2017 15:33:36 -0000 ----==_mimepart_5973704d17b45_b6543f9f1c1d7c3476314 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Artur: makes sense, thanks. @yoavweiss @tarunban curious to hear your thoughts on double-keying. Any implementation gotchas here that we should think through? -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/372#issuecomment-317191115 ----==_mimepart_5973704d17b45_b6543f9f1c1d7c3476314 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Artur: makes sense, thanks.

@yoavweiss @tarunban curious to hear your thoughts on double-keying. Any implementation gotchas here that we should think through?


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_5973704d17b45_b6543f9f1c1d7c3476314-- From nobody Mon Jul 24 09:03:19 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.255 X-Spam-Level: X-Spam-Status: No, score=-3.255 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=gC6P42LvcCuv8TtDCjYDZ4KMSvo=; b=m6wXIZQvAQUBJanF oPFipNvPZStFdXK6JrDh+So8EILdZt+PY6aFWoz3RFO+kPl2DA/G9xxEtPWH+S2h 8o1c8OiW1hmk2c8RsV/8jyMSb+xQS/xh0ny/19d6IZgtmjto6Ipf4CvprMAfVgzq dw7o84hh3AE+ymfBI4CtVDruFGk= Date: Mon, 24 Jul 2017 16:02:43 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Accept-CH-Lifetime privacy concerns (#372) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597619ba47b60_49bc3fa9ca997c2c1323f9"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 24 Jul 2017 16:03:18 -0000 ----==_mimepart_597619ba47b60_49bc3fa9ca997c2c1323f9 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit No implementation gotchas wrt double-keying. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/372#issuecomment-317469814 ----==_mimepart_597619ba47b60_49bc3fa9ca997c2c1323f9 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

No implementation gotchas wrt double-keying.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597619ba47b60_49bc3fa9ca997c2c1323f9-- From nobody Thu Jul 27 18:42:11 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.383 X-Spam-Level: X-Spam-Status: No, score=-0.383 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=tp+W3IiwoTRbhLOTPtDOQ/0Qca4=; b=esA9Kpocqo8abSDw DeaWDF3IWGkN6srRdzPcIo946sslTijSqiVy7iTag5QZYPPWynvhk9Ofyf7SMHKa pY4BSkqMUYC7oRfY/5qxP1in/cforjOEOvpWiD5KZGZabCZgjMSkzW2F1+gfPhgW 6BBHjt+DGCq0AexbIP8H8pI478c= Date: Fri, 28 Jul 2017 01:42:06 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Enabling O(1) removal from digest (#268) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597a966e439bc_337d3fe73f68dc2c258e1"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 28 Jul 2017 01:42:09 -0000 ----==_mimepart_597a966e439bc_337d3fe73f68dc2c258e1 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #268. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/268#event-1182801100 ----==_mimepart_597a966e439bc_337d3fe73f68dc2c258e1 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #268.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597a966e439bc_337d3fe73f68dc2c258e1-- From nobody Thu Jul 27 18:42:16 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.255 X-Spam-Level: X-Spam-Status: No, score=-3.255 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=xmywzlgswKybyvyDZ01dz6VKC+U=; b=m1r5DqPkLvMV/E8q 5aDxE9/1t0eHji8TbxDXVnPIsV/AGtMJ1AJXVWM71Ijbie99HsaifaxsL/ERglyl gHzgFJSwZr+Rh5QvonHG495wF4fmGcI1pTxN1zioZsUfbnehHhdSB5vVDjwCYmX9 scUAuGjF5+JuKV1k1ChafZeHfNI= Date: Fri, 28 Jul 2017 01:42:06 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Enabling O(1) removal from digest (#268) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597a966de5b2f_45963f84023ddc3433433"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 28 Jul 2017 01:42:10 -0000 ----==_mimepart_597a966de5b2f_45963f84023ddc3433433 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Discussed in Prague; absent implementer activity and a concrete proposal, closing. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/268#issuecomment-318532900 ----==_mimepart_597a966de5b2f_45963f84023ddc3433433 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Discussed in Prague; absent implementer activity and a concrete proposal, closing.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597a966de5b2f_45963f84023ddc3433433-- From nobody Fri Jul 28 11:34:52 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.183 X-Spam-Level: X-Spam-Status: No, score=-3.183 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=4b0+7/gpnw8iFGAt9l1RwYznjXo=; b=Sb7n2qA/gdd+XF4s WD2ca9tmDSHR2Eb2i0N+cmVOFU/8XvtC8WDEc0SYMclJRYCFFleT8QcwINtsxnQj NBqGLutvkH/j2YwWIXI4ti0bDjELmacjK6nGXBC1PrtcsWp+UdEAPbL3cmQ4Ahvs ACpD2bFxJ/S8cGeGY/h+/LntvwI= Date: Fri, 28 Jul 2017 18:34:41 +0000 (UTC) To: httpwg/http-extensions Cc: Push In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Scope Accept-CH opt-in to same origin (#373) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597b83c12add2_2c8653fed62005c3c87137"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 28 Jul 2017 18:34:47 -0000 ----==_mimepart_597b83c12add2_2c8653fed62005c3c87137 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @igrigorik pushed 2 commits. 751cc62 extensible list of hints 4e0f1d6 double-keying and secure contexts -- You are receiving this because you are subscribed to this thread. View it on GitHub: https://github.com/httpwg/http-extensions/pull/373/files/a80ad96304c280ed260f75730d77a1f1150b2a56..4e0f1d6f474402e488e90fce223076f9c7378ed1 ----==_mimepart_597b83c12add2_2c8653fed62005c3c87137 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@igrigorik pushed 2 commits.

  • 751cc62 extensible list of hints
  • 4e0f1d6 double-keying and secure contexts


You are receiving this because you are subscribed to this thread.
View it on GitHub or mute the thread.

----==_mimepart_597b83c12add2_2c8653fed62005c3c87137-- From nobody Fri Jul 28 11:38:56 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -2.001 X-Spam-Level: X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=42ITN+GWvExf+oJWmw/N2HOdX/c=; b=gqy77a5NSGa/aO/b jJAdjzXxSBGbtvhiPFGDPMuyfcJtNVUkJMHAY5nLD73rdjAbeQB7RPUnk7OkpCNl P5K5UibE7aAot5dSj0nhBDMXCdJL894G23ybLgzky983qivF3NVtJXDBHBm7COda 8U9g/kd3MhDJnKPS3KqqjWCP5f4= Date: Fri, 28 Jul 2017 18:38:51 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Scope Accept-CH opt-in to same origin (#373) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597b84bac2a7a_3ca43fed62005c3c59368"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 28 Jul 2017 18:38:55 -0000 ----==_mimepart_597b84bac2a7a_3ca43fed62005c3c59368 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @arturjanc thanks for the review. Took another run, with a few large updates: - Accept-CH and Accept-CH-Lifetime should be processed for responses originating from potentially trustworthy origins (i.e. HTTPS-only) - Accept-CH-Lifetime preference should be double-keyed, per discussion in #372. - Consolidated security guidance in one section + tried to rewrite that in light of above updates. I couldn't find any good existing spec examples on double-keying, so would appreciate any guidance on how to explain it here well. @mnot ptal as well, as this is a substantive update. /cc @tarunban @yoavweiss -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/373#issuecomment-318731432 ----==_mimepart_597b84bac2a7a_3ca43fed62005c3c59368 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

@arturja= nc thanks for the review. Took another run, with a few large updates:

  • Accept-CH and Accept-CH-Lifetime should be processed for responses orig= inating from potentially trustworthy origins (i.e. HTTPS-only)
  • Accept-CH-Lifetime preference should be double-keyed, per discussion in= #372.
  • Consolidated security guidance in one section + tried to rewrite that i= n light of above updates.

I couldn't find any good existing spec examples on double-keying, so wou= ld appreciate any guidance on how to explain it here well.

@mnot pta= l as well, as this is a substantive update.

/cc @taru= nban @y= oavweiss

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or mute the thread.3D""

= ----==_mimepart_597b84bac2a7a_3ca43fed62005c3c59368-- From nobody Sun Jul 30 07:30:46 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -4.801 X-Spam-Level: X-Spam-Status: No, score=-4.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=WrScBiyGE9ZRV9Va7yiloJGS37s=; b=NS9X9o2lCPa9Rvej YRpc+XPbMI5o3yPmYAgl7WDF2Tl/S7G3MOzrRBxxApXOg8C5onWD3oXuTN2kpn17 XZBgWEyGVUSC4ahaXd2PDvdSWFZI+QT9S0ktGm1YweA8/gq1P/d7fb9c1mllIaTH GdMQ5csDUkrbRs0CX44yIexAOmM= Date: Sun, 30 Jul 2017 14:30:23 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed Subject: [httpwg/http-extensions] Early Hints and Caching Intermediaries (#374) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ded7f39dc3_1a563fd6875afc38340c5"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 30 Jul 2017 14:30:45 -0000 ----==_mimepart_597ded7f39dc3_1a563fd6875afc38340c5 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable The proposal for the _103 Early Hints_ response contains a few examples ref= erencing (probably caching) intermediaries. For example, to trigger a h2 se= rver-push when an origin sends a 103 carrying `Link` headers. However, ther= e is no explicit definition on what a cache or proxy server may or may not = do with 103 responses. By definition, the informational response cannot have any own meta data: _"A client MUST NOT interpret the 103 (Early Hints) response header fields = as if they applied to the informational response itself"._ Obviously, 103 is not among the status codes cacheable by default defined i= n [RFC7231 6.1](https://tools.ietf.org/html/rfc7231#section-6.1). Furthermo= re the response cannot contain an entity body and it must be considered an = intermediate response as the final response is still to come. I assume all = that forbids storing the 103 in a cache. Considering the objective to speed up Web site delivery, I would like to di= scuss the idea of adding a mechanism that would allow an intermediary cache= to store data from the 103 response. In a CDN-like setup an edge-server first receives an HTTP request and forwa= rds it to the origin. Let's say the final answer took a long time, was priv= ate and could not be stored in the cache. However, a 103 intermediate respo= nse was received in the mean time and forwarded to the client. For subseque= nt requests to the same URL (according to the cache key calculation=E2=80= =A6) the edge cache could send the _cached_ 103 downstream to the client wh= ile the original request is sent upstream to the origin _at the same time_.= I think this could be a very effective way to use waiting time. A similar situation was proposed at the end of section 2, where an _"interm= ediary generates a 103 (Early Hints) response based on the header fields of= a stale-cached=C2=A0response"_. However, this can only apply to cacheable = content. But HTML documents are most often private. To avoid "guessing" in intermediaries, we could define a special Cache Cont= rol header field accompanying the 103 status, such as `Early-Hint-Control`.= An origin could then define a 103 to be cacheable in a proxy server or cac= he. For subsequent requests the stored 103 could be sent downstream regardl= ess of whether the final response is public or private. The header field could follow the `Cache-Control` semantics. The `public` a= nd `max-age=3DN` directives seem appropriate. A proxy server would have to = store the Early Hint information apart from regular responses (e.g. 200) to= not confuse it with a final response. When the field `Early-Hint-Control: = public` is not present, the 103 response should not be stored. --=20 You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/374= ----==_mimepart_597ded7f39dc3_1a563fd6875afc38340c5 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

The proposal for the 103 Early Hints response contains a few ex= amples referencing (probably caching) intermediaries. For example, to trigg= er a h2 server-push when an origin sends a 103 carrying Link h= eaders. However, there is no explicit definition on what a cache or proxy s= erver may or may not do with 103 responses.

By definition, the informational response cannot have any own meta data:=

"A client MUST NOT interpret the 103 (Early Hints) response header f= ields as if they applied to the informational response itself".

Obviously, 103 is not among the status codes cacheable by default define= d in RFC7231 6.= 1. Furthermore the response cannot contain an entity body and it must b= e considered an intermediate response as the final response is still to com= e. I assume all that forbids storing the 103 in a cache.

Considering the objective to speed up Web site delivery, I would like to= discuss the idea of adding a mechanism that would allow an intermediary ca= che to store data from the 103 response.

In a CDN-like setup an edge-server first receives an HTTP request and fo= rwards it to the origin. Let's say the final answer took a long time, was p= rivate and could not be stored in the cache. However, a 103 intermediate re= sponse was received in the mean time and forwarded to the client. For subse= quent requests to the same URL (according to the cache key calculation=E2= =80=A6) the edge cache could send the cached 103 downstream to the= client while the original request is sent upstream to the origin at th= e same time. I think this could be a very effective way to use waiting= time.

A similar situation was proposed at the end of section 2, where an "= intermediary generates a 103 (Early Hints) response based on the header fie= lds of a stale-cached=C2=A0response". However, this can only apply to = cacheable content. But HTML documents are most often private.

To avoid "guessing" in intermediaries, we could define a special Cache C= ontrol header field accompanying the 103 status, such as Early-Hint-C= ontrol. An origin could then define a 103 to be cacheable in a proxy= server or cache. For subsequent requests the stored 103 could be sent down= stream regardless of whether the final response is public or private.

The header field could follow the Cache-Control semantics. = The public and max-age=3DN directives seem approp= riate. A proxy server would have to store the Early Hint information apart = from regular responses (e.g. 200) to not confuse it with a final response. = When the field Early-Hint-Control: public is not present, the = 103 response should not be stored.

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or mute the thread.3D""

= ----==_mimepart_597ded7f39dc3_1a563fd6875afc38340c5-- From nobody Sun Jul 30 21:05:28 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.473 X-Spam-Level: X-Spam-Status: No, score=-5.473 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 30 Jul 2017 21:05:24 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501473924; bh=5tu4ECVGeUbRKdHOB+Kk1Y1/3Yu3iRtJ1bKswwI8nDw=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=wbgL7hljEdCCa2rSoDFLM6qJoegoCjE9ewa68bJuq5IgPAhv6ioLORUeg1r1ZVyk+ GaIiZMFKZyGSHt0GA2krzrFY0IO0eW4uDjcmk2wMPto8LqWSMRYlWRb/Al+dN13nx1 qzzJqblbkN4sKcRjy4nCtju/1AFPjDCQ+jG4rHbo= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Consulting the DNS on expanding ORIGIN set? (#330) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597eac8482942_1565a3ff99b783c30638b6"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 04:05:27 -0000 ----==_mimepart_597eac8482942_1565a3ff99b783c30638b6 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Please review proposed changes in latest commit. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/330#issuecomment-318962268 ----==_mimepart_597eac8482942_1565a3ff99b783c30638b6 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Please review proposed changes in latest commit.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597eac8482942_1565a3ff99b783c30638b6-- From nobody Sun Jul 30 21:07:39 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.382 X-Spam-Level: X-Spam-Status: No, score=-0.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=0inKVe+B5L8+N2WA6knXfvte4A8=; b=TeojLbjnJwj96vJm qQqZ80afg3GHpxMxQNvZgLk6jt6tddlwdPL3K0DirixuoJTSN4kM9XfIfYzvTkkd MK5Hf8kdg5ApoZCmdA0LtREsgt7z6el2d6uJ+Nbc523wkMP8cOEKRLgzkfQ45qMo hqylQCajz/te3KdId3FmuzgzNqs= Date: Mon, 31 Jul 2017 04:07:35 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] ORIGIN and Server Push (#355) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ead0734041_5aeb3fe6878fbc38640d2"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 04:07:37 -0000 ----==_mimepart_597ead0734041_5aeb3fe6878fbc38640d2 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Sounds like there's agreement on #1; closing with no action. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/355#issuecomment-318962474 ----==_mimepart_597ead0734041_5aeb3fe6878fbc38640d2 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Sounds like there's agreement on #1; closing with no action.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597ead0734041_5aeb3fe6878fbc38640d2-- From nobody Sun Jul 30 21:07:45 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.382 X-Spam-Level: X-Spam-Status: No, score=-0.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=45WoMsUPu8w+Eq4UtIc4h4Hp/Vw=; b=jPy6QLo+8sS+cVQ7 XSHhIuok/dvggvkcblL6LUgaFRp/SVvpigy8B9pQ3XcFNSZOL8a/jOGloVwXplxF Gw0I2RweCFA1WbKJVujyCCdIcmL2dxSjal1vJrqTkvQy9VWwlLo8ITrPMyA2hfVg 5FKxYAAoX1ZFVuzk2K0Fm5+TRnI= Date: Mon, 31 Jul 2017 04:07:35 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] ORIGIN and Server Push (#355) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ead0746bf8_221d93feec373dc2c1297f9"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 04:07:38 -0000 ----==_mimepart_597ead0746bf8_221d93feec373dc2c1297f9 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #355. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/355#event-1185076670 ----==_mimepart_597ead0746bf8_221d93feec373dc2c1297f9 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #355.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597ead0746bf8_221d93feec373dc2c1297f9-- From nobody Sun Jul 30 21:11:02 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.181 X-Spam-Level: X-Spam-Status: No, score=-8.181 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 30 Jul 2017 21:10:59 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501474259; bh=tAjLhvGZsqSVbFw9kXAeW89Mce4tCkxR2BtxMyNWibU=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=Os4DLhRUrQ2UKMSqIJdHpgcM2pXbuJzY7/PZ79tB2+X1yz2UOodhZbitegHrd8Sh5 yXWABPe863360tztVSPzPwZFEjlHzwtuGQiup93FMcpND3g10J5f5Bq/t3zF67w7IE COdcyBP9wJqRPfvwh/G1ARrMk1qzlwzAu4h8alNE= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Repetition of Fields (#368) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597eadd3888d1_7bca3fe6878fbc388035f"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 04:11:01 -0000 ----==_mimepart_597eadd3888d1_7bca3fe6878fbc388035f Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #368. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/368#event-1185078568 ----==_mimepart_597eadd3888d1_7bca3fe6878fbc388035f Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #368.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597eadd3888d1_7bca3fe6878fbc388035f-- From nobody Sun Jul 30 21:13:22 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.382 X-Spam-Level: X-Spam-Status: No, score=-0.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=gI7h1MCNapBCm56u5yr8cAatCGg=; b=SLHvFZBHB98yAcvI 80fG+R3TV3IOwe8Cey2j3TEpaeVRkrSbmrwhFbSyDWG5T5CnThReXnDtfDDtSSBy Z6PfnzQGiOohAiK2sAxJnvvTI4gvrV75UTSfjHEj0c9MTFFoulcOA4GShCsU+nd9 NqcMzX4M885VWAaI+tcufLQ6K7M= Date: Mon, 31 Jul 2017 04:13:19 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Non-normative processing algorithm (#370) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597eae5ecc02d_652d3ffa98ba9c307444e"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 04:13:21 -0000 ----==_mimepart_597eae5ecc02d_652d3ffa98ba9c307444e Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #370 via 86d32e48f5738233ceb0f03994ad7e10d35703b8. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/370#event-1185079895 ----==_mimepart_597eae5ecc02d_652d3ffa98ba9c307444e Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #370 via 86d32e4.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597eae5ecc02d_652d3ffa98ba9c307444e-- From nobody Sun Jul 30 21:33:26 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.402 X-Spam-Level: X-Spam-Status: No, score=-0.402 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=iHvxPghrIbc4LovrgDsEZ9c8MpI=; b=pv0AuJHIfcrw4snT ImeBmkqMhrjujqIaNrYKtj2PFOpQXgiQSGlvElx7DGT3MtB53WgrwTDYxYCQHlTs 4g6Yr0zyon9++D0O8W28KlUXp5lPz65B4kbyOm7KVeNUUSS58HZW/TjFVHlcHUqy crQUKgdDQ2svw0QTohuicyQA16U= Date: Mon, 31 Jul 2017 04:33:22 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] ORIGIN and server authority (#349) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597eb31237bb1_1853b3ff99b783c30919f0"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 04:33:25 -0000 ----==_mimepart_597eb31237bb1_1853b3ff99b783c30919f0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #349 via cab1cc50ac7a12644555b34a864ac0ad8124fef3. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/349#event-1185090455 ----==_mimepart_597eb31237bb1_1853b3ff99b783c30919f0 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #349 via cab1cc5.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597eb31237bb1_1853b3ff99b783c30919f0-- From nobody Sun Jul 30 21:36:09 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.382 X-Spam-Level: X-Spam-Status: No, score=-0.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=GGGp0XWmNJanb3wqweRP9mXGTWQ=; b=VmjBLPyMqf0R275c 84/XPB6WykepscVk5VvbYPYJlF9H5xSfv4DkR/isPtJu3jQMH5VMR93VrHL8bo09 p0Arb3wDivrJjbZ2+Aod3ureN7/z5eEsGT2YukKJ9odXqnyQ7hwu9UdJq/g3BZJR Xzd0cCWwzc18wdOL79cFBoFZnbg= Date: Mon, 31 Jul 2017 04:36:06 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Expectations of Origin Set Size (#369) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597eb3b6ead2_72313fb591889c2c8608d"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 04:36:08 -0000 ----==_mimepart_597eb3b6ead2_72313fb591889c2c8608d Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #369 via 8b3b56bd17dccec24386a1916f6e7975b0bc3da3. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/369#event-1185091805 ----==_mimepart_597eb3b6ead2_72313fb591889c2c8608d Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #369 via 8b3b56b.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597eb3b6ead2_72313fb591889c2c8608d-- From nobody Sun Jul 30 21:36:53 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.454 X-Spam-Level: X-Spam-Status: No, score=-0.454 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=QFWangL4Lu1unBG4A2YQT8M3m/s=; b=AXrjGsF4Icf5YnuL MtXqj4/Kbvo9tf2y4/w7/2KH6fVLNV+B0SMKKQeNnA1gH2Mj0WXmtp7498JC/1XM MQDVe1QOY/ip5ZmZOOLt0zZhuKBGhl1VinRNrToYev93M1003PVOz5f6zqnTkgYJ HBspXMzxlOPXNHBsbN4KzNxusvU= Date: Mon, 31 Jul 2017 04:36:49 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Explain interactions with Alt-Svc (#348) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597eb3e1654bc_2573fcece693c3c121412"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 04:36:52 -0000 ----==_mimepart_597eb3e1654bc_2573fcece693c3c121412 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Are you going to take another go at this? -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/348#issuecomment-318965361 ----==_mimepart_597eb3e1654bc_2573fcece693c3c121412 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Are you going to take another go at this?


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597eb3e1654bc_2573fcece693c3c121412-- From nobody Sun Jul 30 21:54:59 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.453 X-Spam-Level: X-Spam-Status: No, score=-5.453 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 30 Jul 2017 21:54:56 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501476896; bh=Esd7CTr4fcceZR1v25Di4xGNm/bm+FvT4U3U5w7hrlA=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=TiTul4Qd/rshaUyvNyROcOePjCoZ6lDOgokZ4s53B7gh85ql6F7K5X2D+TL9eeEcD QAA1SKbZ2XpZ8UDWUAYwCgaSqzf/bzOQOoeqOEnIvHShqZOpgQnreVusNJ3vudJW1Z rklpJ1LrfHl0CunytVdijMBk0e+GJBhmBmoM9viQ= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Explain interactions with Alt-Svc (#348) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597eb82020433_7dd03fe54cfb5c2c89284"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 04:54:58 -0000 ----==_mimepart_597eb82020433_7dd03fe54cfb5c2c89284 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Sorry, I let this one drop because I missed your suggest, which is good. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/348#issuecomment-318967356 ----==_mimepart_597eb82020433_7dd03fe54cfb5c2c89284 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Sorry, I let this one drop because I missed your suggest, which is good.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597eb82020433_7dd03fe54cfb5c2c89284-- From nobody Sun Jul 30 21:55:59 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.182 X-Spam-Level: X-Spam-Status: No, score=-3.182 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=bLVyMZVR/dzMQ6AUxTeQpOZQvUE=; b=Efc+y6kuBXw+Ib+i yuM+uKl1BUEX6JsGBqEkytokP8fIgbUd7RJacasf19BjN/rKq4LK/ALQBOjRdoNA IjArbG/aeiKSFAewQcwdk+w5wUqP8PtLBF6QQSsHKkAppQeQ0Q0iHhqCUW0gpm4F ilClsG+w0z7svHAb6rJskWDocZA= Date: Mon, 31 Jul 2017 04:55:55 +0000 (UTC) To: httpwg/http-extensions Cc: Push In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Explain interactions with Alt-Svc (#348) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597eb85aee27b_2f8b3fa9730b9c38759de"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 04:55:58 -0000 ----==_mimepart_597eb85aee27b_2f8b3fa9730b9c38759de Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @martinthomson pushed 1 commit. b6c50a9 Use the actual reference -- You are receiving this because you are subscribed to this thread. View it on GitHub: https://github.com/httpwg/http-extensions/pull/348/files/ac03c89a36aa499904e482ea5e440ab44e0f0b9f..b6c50a93213ee475ab4552d6d3aff7db07ebda6a ----==_mimepart_597eb85aee27b_2f8b3fa9730b9c38759de Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@martinthomson pushed 1 commit.


You are receiving this because you are subscribed to this thread.
View it on GitHub or mute the thread.

----==_mimepart_597eb85aee27b_2f8b3fa9730b9c38759de-- From nobody Sun Jul 30 22:17:46 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.396 X-Spam-Level: X-Spam-Status: No, score=-3.396 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=LTNNyUV12DIRZ2X+2DiPhIlWwcA=; b=X1DbTTlLwe6nmz8e 2mFFYq8rvavOPUIngh521zF5Tuht/MHx6QtweKlJu6LUVnT2BilAwMgK1MSWyGwA izG+RQ5YkHqBUdBcSqSNVaH88D8Wd/gOnjBqto3+8VraVvLThKtgfBqZIufyaxfI V7uJ9RzQFMncOZoMF0xucNiv4Cw= Date: Mon, 31 Jul 2017 05:17:41 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Explain interactions with Alt-Svc (#348) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ebd75b3d49_12093fe0255bdc3c140820"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 05:17:45 -0000 ----==_mimepart_597ebd75b3d49_12093fe0255bdc3c140820 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit mnot commented on this pull request. > @@ -144,12 +144,12 @@ See {{algo}} for an illustrative algorithm for processing ORIGIN frames. The set of origins (as per {{!RFC6454}}) that a given connection might be used for is known in this specification as the Origin Set. -By default, a connection's Origin Set is uninitialised. When an ORIGIN frame is first received and -successfully processed by a client, the connection's Origin Set is defined to contain a single -origin, composed from: +By default, a connections's Origin Set is uninitialised. When an ORIGIN frame is first received connections's? -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/348#pullrequestreview-53128301 ----==_mimepart_597ebd75b3d49_12093fe0255bdc3c140820 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@mnot commented on this pull request.


In draft-ietf-httpbis-origin-frame.md:

> @@ -144,12 +144,12 @@ See {{algo}} for an illustrative algorithm for processing ORIGIN frames.
 The set of origins (as per {{!RFC6454}}) that a given connection might be used for is known in this
 specification as the Origin Set.
 
-By default, a connection's Origin Set is uninitialised. When an ORIGIN frame is first received and
-successfully processed by a client, the connection's Origin Set is defined to contain a single
-origin, composed from:
+By default, a connections's Origin Set is uninitialised. When an ORIGIN frame is first received

connections's?


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597ebd75b3d49_12093fe0255bdc3c140820-- From nobody Sun Jul 30 22:28:34 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.395 X-Spam-Level: X-Spam-Status: No, score=-8.395 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 30 Jul 2017 22:28:30 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501478910; bh=ccVHVTKqOityp2HnW3Lxzw46jBjKeNt4JhUha+feshE=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=xg0MHMJNhzlju20s+rCriAJ11WPA8yT7x7o/0ofNPGH5q54OvlyqApEH2eH2Ix1N3 9P2E6EoO7l1kU5d8uD7x3GinP1G8+ROQwIYIiBQYFqnxDZNSFxU0NuV/xTb+fHiHXc U2NhU2cq4cfUmEzgDZ4LO1iXi3HDf7p2zMg9plxg= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Explain interactions with Alt-Svc (#348) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ebffe50dd6_6a0f3fcece693c3c220465"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 05:28:33 -0000 ----==_mimepart_597ebffe50dd6_6a0f3fcece693c3c220465 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit martinthomson commented on this pull request. > @@ -144,12 +144,12 @@ See {{algo}} for an illustrative algorithm for processing ORIGIN frames. The set of origins (as per {{!RFC6454}}) that a given connection might be used for is known in this specification as the Origin Set. -By default, a connection's Origin Set is uninitialised. When an ORIGIN frame is first received and -successfully processed by a client, the connection's Origin Set is defined to contain a single -origin, composed from: +By default, a connections's Origin Set is uninitialised. When an ORIGIN frame is first received Your text, not mine, but I'll fix it. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/348#discussion_r130274444 ----==_mimepart_597ebffe50dd6_6a0f3fcece693c3c220465 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@martinthomson commented on this pull request.


In draft-ietf-httpbis-origin-frame.md:

> @@ -144,12 +144,12 @@ See {{algo}} for an illustrative algorithm for processing ORIGIN frames.
 The set of origins (as per {{!RFC6454}}) that a given connection might be used for is known in this
 specification as the Origin Set.
 
-By default, a connection's Origin Set is uninitialised. When an ORIGIN frame is first received and
-successfully processed by a client, the connection's Origin Set is defined to contain a single
-origin, composed from:
+By default, a connections's Origin Set is uninitialised. When an ORIGIN frame is first received

Your text, not mine, but I'll fix it.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597ebffe50dd6_6a0f3fcece693c3c220465-- From nobody Sun Jul 30 22:29:19 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.181 X-Spam-Level: X-Spam-Status: No, score=-8.181 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 30 Jul 2017 22:29:15 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501478955; bh=8TJEul9I2mdCSOHYwjyn0UK3jH/1HO1wADcz2pbnVzI=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=CAAcve+2MePJ2kvm47TKyU1hOilIORWt0RxkJLUaqjwHfwZGr6xA+pGncExVuX5Um SrDBumq1PpccJ9Uo5WrEPSLowCumkm1vfasnH1JPUz2HkfDjaJlnRMh9aEQ+zmHeHi +Fw3Ng1jmH4lmdVBlF0ghYWkpp3BZTxWsz/jLDa4= To: httpwg/http-extensions Cc: Push In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Explain interactions with Alt-Svc (#348) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ec02bda658_4ad73f9239329c3039481"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 05:29:18 -0000 ----==_mimepart_597ec02bda658_4ad73f9239329c3039481 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit @martinthomson pushed 1 commit. 73c9519 connections's -- You are receiving this because you are subscribed to this thread. View it on GitHub: https://github.com/httpwg/http-extensions/pull/348/files/b6c50a93213ee475ab4552d6d3aff7db07ebda6a..73c9519656ce52643878de6d3e240fb299edb943 ----==_mimepart_597ec02bda658_4ad73f9239329c3039481 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@martinthomson pushed 1 commit.


You are receiving this because you are subscribed to this thread.
View it on GitHub or mute the thread.

----==_mimepart_597ec02bda658_4ad73f9239329c3039481-- From nobody Sun Jul 30 22:29:33 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.595 X-Spam-Level: X-Spam-Status: No, score=-5.595 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 30 Jul 2017 22:29:30 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501478970; bh=Vy184BS/cjt+kPN11zxy8p9iInx/X9Hf+CE+zox3jDI=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=n3oeTwxMucAVnJFVDtYXnsmrqa95ZaBs/yrkmVGqnv4Go9jXSahKKPUKAP5mUZFlU DP7KSKsXd1lyxCzJCiYQwRK9NQL6yvfpT3Qg+RiEmAe2O1WKeAKuT6WiHU0hWUa7Gs Hmpjk7sVTb7SZW1sGknwGH8Cwbsm4Y2rihnjlsDU= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Explain interactions with Alt-Svc (#348) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ec03a1fb7c_4ef43fe54cfb5c2c3954"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 05:29:32 -0000 ----==_mimepart_597ec03a1fb7c_4ef43fe54cfb5c2c3954 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit martinthomson commented on this pull request. > @@ -144,12 +144,12 @@ See {{algo}} for an illustrative algorithm for processing ORIGIN frames. The set of origins (as per {{!RFC6454}}) that a given connection might be used for is known in this specification as the Origin Set. -By default, a connection's Origin Set is uninitialised. When an ORIGIN frame is first received and -successfully processed by a client, the connection's Origin Set is defined to contain a single -origin, composed from: +By default, a connections's Origin Set is uninitialised. When an ORIGIN frame is first received OK, it's mine apparently -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/348#discussion_r130274517 ----==_mimepart_597ec03a1fb7c_4ef43fe54cfb5c2c3954 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

@martinthomson commented on this pull request.


In draft-ietf-httpbis-origin-frame.md:

> @@ -144,12 +144,12 @@ See {{algo}} for an illustrative algorithm for processing ORIGIN frames.
 The set of origins (as per {{!RFC6454}}) that a given connection might be used for is known in this
 specification as the Origin Set.
 
-By default, a connection's Origin Set is uninitialised. When an ORIGIN frame is first received and
-successfully processed by a client, the connection's Origin Set is defined to contain a single
-origin, composed from:
+By default, a connections's Origin Set is uninitialised. When an ORIGIN frame is first received

OK, it's mine apparently


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597ec03a1fb7c_4ef43fe54cfb5c2c3954-- From nobody Sun Jul 30 23:43:19 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.181 X-Spam-Level: X-Spam-Status: No, score=-8.181 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 30 Jul 2017 23:43:16 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501483396; bh=v0gsp8xkzRC69x74jClcmITEEuQhcygmCCbYn1eTpC8=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=1/gKkxaCI3CGRSJonFWvvBC+bfwJr0qDsRfdgnnir0GxZu3cH6yz8lS5ILHReKo88 BZ+vut5x3wKp3rYZA4y0MPrwV4pSUEg7shrSp1tqNa8mnQfUXaA13eFK+UoZ0hhc4+ qfRLF7lQ2yDNvnbCF/Wat8oFxEaAZn3hv46drgbQ= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Explain interactions with Alt-Svc (#348) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ed1847e581_338e3fd228405c3813109e"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 06:43:18 -0000 ----==_mimepart_597ed1847e581_338e3fd228405c3813109e Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Merged #348. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/348#event-1185186329 ----==_mimepart_597ed1847e581_338e3fd228405c3813109e Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Merged #348.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597ed1847e581_338e3fd228405c3813109e-- From nobody Sun Jul 30 23:43:27 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.454 X-Spam-Level: X-Spam-Status: No, score=-0.454 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=OhOzGA0h/l87YM3jTows7rbI34s=; b=sxXG2pzViBZX86Kn 1VnoJfhjkmlYCYfLijJRCMZdqmbxjwDOOTdaPXTD1BpWYAgx97BAOHPiJfVG/FJS wF+8GHlFtslS/iYm8mU7KraWz+utHN7EaC0i9e71LoG/KLLR4Zy5x8IrpTRgpZg3 pYctcTtf1JMh1YrAddzI3W1EaIs= Date: Mon, 31 Jul 2017 06:43:22 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Explain interactions with Alt-Svc (#348) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ed18a43137_66793fcece693c3c14862d"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 06:43:26 -0000 ----==_mimepart_597ed18a43137_66793fcece693c3c14862d Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Thanks! -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/pull/348#issuecomment-318982152 ----==_mimepart_597ed18a43137_66793fcece693c3c14862d Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Thanks!


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597ed18a43137_66793fcece693c3c14862d-- From nobody Sun Jul 30 23:43:50 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.253 X-Spam-Level: X-Spam-Status: No, score=-8.253 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Sun, 30 Jul 2017 23:43:46 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501483427; bh=JXeUtGq6A1X/U/H4N8Yyo6PLeTHntjoHQHoUHzl+24U=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=dnWeTGA830FtaS+SVhvj1IfSj2f/hwjzhvJ8n1nZw/uFvRkbdRXjmgdXpNHdlwsew M8gkZ7sN9IdpVkjwqmZErYzT68UhzG8li6UYjyNd1lkcV7udowb4HJfu1nMvC8IIrY X8rYybqmlH35m2KSFYpOeqQpzdUQ6HC/U50vqmUw= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Origin set definition (and port interaction with Alt-Svc) (#331) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ed1a2f2431_35703f9239329c3063187"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 06:43:49 -0000 ----==_mimepart_597ed1a2f2431_35703f9239329c3063187 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit That worked out well - thx mt. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/331#issuecomment-318982208 ----==_mimepart_597ed1a2f2431_35703f9239329c3063187 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

That worked out well - thx mt.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597ed1a2f2431_35703f9239329c3063187-- From nobody Sun Jul 30 23:43:55 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.402 X-Spam-Level: X-Spam-Status: No, score=-0.402 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=AwCiIzqJLVrQ8IdbGWQTnB5orRw=; b=dr/reJMBPS8ZXy5K rDxjW9Str6H5oyhEN3ZlviIKitCtbiH+KJ0oGhsM8Tf5iqU+HyCsfqHrP/tUuYU6 pJFoFIz8d0g+M3k10VGgbiKEv1qDSxh0yWpWGcq052eZt/k2y18u97nZW+FGIpr6 4RDMKEW5XI2uz2kjVaDji/y+ULM= Date: Mon, 31 Jul 2017 06:43:47 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Origin set definition (and port interaction with Alt-Svc) (#331) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597ed1a37e4e_1a5123ff99b783c30392c6"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 06:43:50 -0000 ----==_mimepart_597ed1a37e4e_1a5123ff99b783c30392c6 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #331. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/331#event-1185186780 ----==_mimepart_597ed1a37e4e_1a5123ff99b783c30392c6 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #331.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597ed1a37e4e_1a5123ff99b783c30392c6-- From nobody Mon Jul 31 05:56:14 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.382 X-Spam-Level: X-Spam-Status: No, score=-0.382 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=CWKyZpXRr0AXLRLH+UgRe2Ol17s=; b=MhY0qIpp1RiT3rXm 6Bo/lOpy6UVIfAiDN9QI+hxnND0ZyPVFVFO3DYnSj62LML8d87dq3SkX8/kW+AHo w8tQiji/ZMGRZoYe6nA84UBZ88q2LO+EcqGB0rhGG+Iyr8Tc4ChbWoFvOxsLEyh7 Q8YzMkZ+Sn8VWygLurm/SCdqqXM= Date: Mon, 31 Jul 2017 12:56:07 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Early Hints and Caching Intermediaries (#374) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597f28e77c17a_3e433f902f36bc2c1421ab"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 12:56:12 -0000 ----==_mimepart_597f28e77c17a_3e433f902f36bc2c1421ab Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit The early hints document has completed both WG and IETF last call so it should not be re-opened for new features. It sounds like you're suggesting new work - and httpbis is open to taking on new work. You should suggest that, even better with a draft, on the mailing list. Thanks. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/374#issuecomment-319059043 ----==_mimepart_597f28e77c17a_3e433f902f36bc2c1421ab Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

The early hints document has completed both WG and IETF last call so it = should not be re-opened for new features.

It sounds like you're suggesting new work - and httpbis is open to takin= g on new work. You should suggest that, even better with a draft, on the ma= iling list.

Thanks.

&mda= sh;
You are receiving this because you are subscribed to this thread.<= br />Reply to this email directly, view it on GitHub, or <= a href=3D"https://github.com/notifications/unsubscribe-auth/AORpyFSYc94P0yQ= MnlynsFbrtGEXutXjks5sTc7ngaJpZM4OnpnW">mute the thread.3D""

= ----==_mimepart_597f28e77c17a_3e433f902f36bc2c1421ab-- From nobody Mon Jul 31 05:56:25 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.402 X-Spam-Level: X-Spam-Status: No, score=-0.402 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=UEDHrEFktIihKMGa8oDBD3DdGQs=; b=d+jv9wj8EJeP23pU jG2KvEKbTJH9b5DCja4lsd/jW+I0NUHviNun0f8E0bqSFj7zaYMJpI2Pw+iPHc81 t9zFolK82SXy8ryz0dDN4pw7VeQbEoJhDSQ4aDlE9qSzecitBpKYTyJbVBeAJHD0 bkrhUYG5/ocPamTNlNmS/kuz6RM= Date: Mon, 31 Jul 2017 12:56:08 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Early Hints and Caching Intermediaries (#374) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597f28e8164ef_530b3fd6b8ee7c34937bc"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 12:56:18 -0000 ----==_mimepart_597f28e8164ef_530b3fd6b8ee7c34937bc Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Closed #374. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/374#event-1185703670 ----==_mimepart_597f28e8164ef_530b3fd6b8ee7c34937bc Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Closed #374.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597f28e8164ef_530b3fd6b8ee7c34937bc-- From nobody Mon Jul 31 16:32:34 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -8.181 X-Spam-Level: X-Spam-Status: No, score=-8.181 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Mon, 31 Jul 2017 16:32:29 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501543949; bh=gaVC4bhUEPFNnvUgnNptF0AZ7vDcWCSOkwUPEn9wtNU=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=kEzNTCYgtnRfsFd7EdPL45vAT6pM56aantXBsVh2FWyp0Uc1gYYh5iQKXKuQ+ZkbL NygQ9tUEFt5YW40Wtg4ML6WfgjNT5GKyUSAks4TJKZCvjHiR5kGyUihSIB84R/glgx aSeuEPntBv1gI4ptkk3U9VCt26heIj6U1uAXTsv8= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Consulting the DNS on expanding ORIGIN set? (#330) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597fbe0da84e9_57813fef5e885c3815936e"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 23:32:32 -0000 ----==_mimepart_597fbe0da84e9_57813fef5e885c3815936e Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit I see the associated suggestions in the Security Considerations, but I thought the discussion on the list led toward putting a "MAY skip, but SHOULD use something else instead"? Even if the concrete suggestions of what the "something else" could be still live in Security Considerations.... -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/330#issuecomment-319225608 ----==_mimepart_597fbe0da84e9_57813fef5e885c3815936e Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

I see the associated suggestions in the Security Considerations, but I= thought the discussion on the list led toward putting a "MAY skip, but S= HOULD use something else instead"? Even if the concrete suggestions of w= hat the "something else" could be still live in Security Considerations..= ..

&m= dash;
You are receiving this because you are subscribed to this thre= ad.
Reply to this email directly, view it on GitHub, or mute the thread.

=
----==_mimepart_597fbed0a3efa_19603fc3b9979c3c91958-- From nobody Mon Jul 31 16:39:59 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.615 X-Spam-Level: X-Spam-Status: No, score=-5.615 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Mon, 31 Jul 2017 16:39:55 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501544395; bh=zyVzofNDre5dEmIUHnBeAzXKH+p0poqLypbJYVZPs1M=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=EgFJoE8Uc9b4cHLNUlIgPAfIBLVUGjujsgfGznAFf8hUO3hqRwoqSk7wp+FdC2ERH FO2XQDXUQYIfB5qZTqUTqjyprdjlbo6lzFuQrdLqmkqHrBmPQDuUbyypP2yhzK53fl mg4vMtA5z6tis0oC0B9+zZyHhv2qPEXBypR47dzU= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Consulting the DNS on expanding ORIGIN set? (#330) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597fbfcb54275_a283fad49b35c3c98761"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 23:39:58 -0000 ----==_mimepart_597fbfcb54275_a283fad49b35c3c98761 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit On the thread, "Clients opting not to check DNS SHOULD employ some alternative means to increase confidence that the certificate is legitimate, such as Certificate Transparency or revocation checks" got +1s from Ryan and @enygren. Since you have a mention elsewhere, you could adapt that to "such as those discussed in Section 4" reasonably enough. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/330#issuecomment-319226728 ----==_mimepart_597fbfcb54275_a283fad49b35c3c98761 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable

On the thread, "Clients opting not to check DNS SHOULD employ some alt= ernative means to increase confidence that the certificate is legitimate,= such as Certificate Transparency or revocation checks" got +1s from Ryan= and @enygr= en. Since you have a mention elsewhere, you could adapt that to "suc= h as those discussed in Section 4" reasonably enough.

&m= dash;
You are receiving this because you are subscribed to this thre= ad.
Reply to this email directly, view it on GitHub, or mute the thread.

=
= ----==_mimepart_597fbfcb54275_a283fad49b35c3c98761-- From nobody Mon Jul 31 16:52:38 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -5.473 X-Spam-Level: X-Spam-Status: No, score=-5.473 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com Date: Mon, 31 Jul 2017 16:52:33 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=github.com; s=pf2014; t=1501545153; bh=Vl4f/EB9+PGJxLCNtkwKqO8GQeR15Zf+mieoxzYKykU=; h=From:Reply-To:To:Cc:In-Reply-To:References:Subject:List-ID: List-Archive:List-Post:List-Unsubscribe:From; b=AIFgHGG4mjirnejapQu25JfdZ9FR+nIfjkaXJ/juB5Zw2fdS9QTsWd8pzIoSh+hg7 xC8j8O2hz1s5/b5VjNGw7aZgUhYikTQAmss4c/N9gRQGl+o3qz1XgV4roIzQxw3JFR 3jlrW6jkHN+97j1Au8zIG7KuUlLnhcLSG5+Qo72s= To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Consulting the DNS on expanding ORIGIN set? (#330) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597fc2c1e1e83_1d11a3ff9f0f71c301211d4"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Jul 2017 23:52:36 -0000 ----==_mimepart_597fc2c1e1e83_1d11a3ff9f0f71c301211d4 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Hmm. I suspect a requirement that's so vague won't get through IESG, but I guess we can try it. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/330#issuecomment-319228529 ----==_mimepart_597fc2c1e1e83_1d11a3ff9f0f71c301211d4 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Hmm. I suspect a requirement that's so vague won't get through IESG, but I guess we can try it.


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597fc2c1e1e83_1d11a3ff9f0f71c301211d4-- From nobody Mon Jul 31 17:57:51 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -3.183 X-Spam-Level: X-Spam-Status: No, score=-3.183 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=ei1qmz4HacDKaCxvDETWewM8OBE=; b=A1GnI5aAm4ydsUJW ZIk/EpCQ8Tsbl/DOcWKGLuCcX6dz9jLD/u4LnsXuYGj4G5BPfp00RgRXmY9pqZju 2l/v02QQGSwmBS+ZpC6/LgKClekjsK7DKnJdT87UCXHsZShBOBa0Sqnp/RxVoF+Y zeSZOwJXxZRMYqTLSIGy1IGpXAI= Date: Tue, 01 Aug 2017 00:57:47 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] multiple 103s are cumulating or overwriting headers? (#371) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597fd20ae0770_5df63ff95f7c9c3079978"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 01 Aug 2017 00:57:49 -0000 ----==_mimepart_597fd20ae0770_5df63ff95f7c9c3079978 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Also, this is a general problem with the HTTP caching model, not specific to 103. See: https://github.com/httpwg/http11bis/issues/29 -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/371#issuecomment-319237590 ----==_mimepart_597fd20ae0770_5df63ff95f7c9c3079978 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Also, this is a general problem with the HTTP caching model, not specific to 103. See:
httpwg/http11bis#29


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597fd20ae0770_5df63ff95f7c9c3079978-- From nobody Mon Jul 31 17:58:43 2017 Delivered-To: http-issues@ietfa.amsl.com X-Spam-Flag: NO X-Spam-Score: -0.403 X-Spam-Level: X-Spam-Status: No, score=-0.403 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=9Hv8cMRowvxholK11XsqXWkzaHY=; b=TTXX5vN5lBT4xaRN S85a43ElrrUBRqej4lELAib25HnQ9+1glkyFbkYArYISf/8fneC9vYzCr01qA3Dm YsBBu6AVTKvDi0SPPgAUDlT8esBxXbfWt3eWX3K0/5bbvyCFTNXEFOWKZo/Qk5KP eRqTo2nJjY7goPPuIYt9VDlR7PM= Date: Tue, 01 Aug 2017 00:58:38 +0000 (UTC) To: httpwg/http-extensions Cc: Subscribed In-Reply-To: References: Subject: Re: [httpwg/http-extensions] Early Hints and Caching Intermediaries (#374) Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="--==_mimepart_597fd23dceabf_70973fed6290bc3c31956"; charset=UTF-8 Content-Transfer-Encoding: 7bit Precedence: list Archived-At: Message-ID: From: HTTP issue updates Reply-To: http-issues@ietf.org X-BeenThere: http-issues@ietf.org X-Mailman-Version: 2.1.22 List-Id: HTTP issue updates List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 01 Aug 2017 00:58:42 -0000 ----==_mimepart_597fd23dceabf_70973fed6290bc3c31956 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Also, this is a general problem with the HTTP caching model, not specific to 103. See: httpwg/http11bis#29 -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/httpwg/http-extensions/issues/374#issuecomment-319237704 ----==_mimepart_597fd23dceabf_70973fed6290bc3c31956 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Also, this is a general problem with the HTTP caching model, not specific to 103. See:
httpwg/http11bis#29


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.

----==_mimepart_597fd23dceabf_70973fed6290bc3c31956--