Return-Path: <mchurch@amsl.com>
X-Original-To: http-state@ietfa.amsl.com
Delivered-To: http-state@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
	by ietfa.amsl.com (Postfix) with ESMTP id 2B737C1E7250
	for <http-state@ietfa.amsl.com>; Mon,  6 Jan 2025 09:42:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.905
X-Spam-Level: 
X-Spam-Status: No, score=-1.905 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_BLOCKED=0.001,
	RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001,
	RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001,
	RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001,
	T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001,
	URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194])
	by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id cyj3gcUag8fc for <http-state@ietfa.amsl.com>;
	Mon,  6 Jan 2025 09:42:10 -0800 (PST)
Received: from c8a.amsl.com (c8a.amsl.com [4.31.198.40])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by ietfa.amsl.com (Postfix) with ESMTPS id 5E5BAC1E7259
	for <http-state@ietf.org>; Mon,  6 Jan 2025 09:42:10 -0800 (PST)
Received: from localhost (localhost [127.0.0.1])
	by c8a.amsl.com (Postfix) with ESMTP id 4CA45425A392;
	Mon,  6 Jan 2025 09:42:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
Received: from c8a.amsl.com ([127.0.0.1])
	by localhost (c8a.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id ZmujMzvT2zGY; Mon,  6 Jan 2025 09:42:10 -0800 (PST)
Received: from smtpclient.apple (unknown [199.192.157.25])
	by c8a.amsl.com (Postfix) with ESMTPSA id BD737425A391;
	Mon,  6 Jan 2025 09:42:09 -0800 (PST)
Content-Type: text/plain;
	charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3776.700.51\))
From: Madison Church <mchurch@amsl.com>
In-Reply-To: <20250106141547.580ED1F5420@rfcpa.rfc-editor.org>
Date: Mon, 6 Jan 2025 11:41:58 -0600
Content-Transfer-Encoding: quoted-printable
Message-Id: <6618AF47-084F-4E21-97ED-C8DD70E24A93@amsl.com>
References: <20250106141547.580ED1F5420@rfcpa.rfc-editor.org>
To: Orie Steele <orie@transmute.industries>,
 "Murray S. Kucherawy" <superuser@gmail.com>
X-Mailer: Apple Mail (2.3776.700.51)
Message-ID-Hash: 3OCK675O7P7REAGQN5O3Q2ZMQC6ECPS5
X-Message-ID-Hash: 3OCK675O7P7REAGQN5O3Q2ZMQC6ECPS5
X-MailFrom: mchurch@amsl.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-http-state.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
CC: RFC Editor <rfc-editor@rfc-editor.org>, vladimir.gorej@gmail.com,
 abarth@eecs.berkeley.edu, http-state@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5Bhttp-state=5D_Re=3A_=5BEditorial_Errata_Reported=5D_RFC6265_=28?=
	=?utf-8?q?8242=29?=
List-Id: Discuss HTTP State Management Mechanism <http-state.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/http-state/qYKb66srjtQfEDTq5iz-6IUs5_M>
List-Archive: <https://mailarchive.ietf.org/arch/browse/http-state>
List-Help: <mailto:http-state-request@ietf.org?subject=help>
List-Owner: <mailto:http-state-owner@ietf.org>
List-Post: <mailto:http-state@ietf.org>
List-Subscribe: <mailto:http-state-join@ietf.org>
List-Unsubscribe: <mailto:http-state-leave@ietf.org>

Hi Murray and Orie,

We are unable to verify this erratum that the submitter marked as =
editorial, so we changed the Type to =E2=80=9CTechnical=E2=80=9D. As =
Stream Approver, please review and set the Status and Type accordingly =
(see the definitions at https://www.rfc-editor.org/errata-definitions/).=20=


Note that we are sending this to both of you as ADs of the ART Area as =
the httpstate WG has concluded.

You may review the report at: https://www.rfc-editor.org/errata/eid8242=20=


Information on how to verify errata reports can be found at: =
https://www.rfc-editor.org/how-to-verify/=20

Further information on errata can be found at: =
https://www.rfc-editor.org/errata.php.=20

Thank you,=20
RFC Editor/mc

> On Jan 6, 2025, at 8:15=E2=80=AFAM, RFC Errata System =
<rfc-editor@rfc-editor.org> wrote:
>=20
> The following errata report has been submitted for RFC6265,
> "HTTP State Management Mechanism".
>=20
> --------------------------------------
> You may review the report below and at:
> https://www.rfc-editor.org/errata/eid8242
>=20
> --------------------------------------
> Type: Editorial
> Reported by: Vladim=C3=ADr Gorej <vladimir.gorej@gmail.com>
>=20
> Section: 4.1.1
>=20
> Original Text
> -------------
> cookie-value      =3D *cookie-octet / ( DQUOTE *cookie-octet DQUOTE )
>=20
> Corrected Text
> --------------
> cookie-value      =3D ( DQUOTE *cookie-octet DQUOTE ) / *cookie-octet
>=20
> Notes
> -----
> Many parsers process ABNF alternatives left-to-right and do not =
backtrack if an alternative partially matches but ultimately fails. This =
is why placing *cookie-octet first can cause issues.
>=20
> The quoted pattern ( DQUOTE *cookie-octet DQUOTE ) is more specific =
than the unquoted pattern *cookie-octet. Placing it first ensures that =
the parser prioritizes correctly. Quoted values are matched as a whole =
first. If the value isn=E2=80=99t quoted, the parser safely falls back =
to checking for unquoted *cookie-octet.
>=20
> Instructions:
> -------------
> This erratum is currently posted as "Reported". (If it is spam, it=20
> will be removed shortly by the RFC Production Center.) Please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party =20
> will log in to change the status and edit the report, if necessary.
>=20
> --------------------------------------
> RFC6265 (draft-ietf-httpstate-cookie-23)
> --------------------------------------
> Title               : HTTP State Management Mechanism
> Publication Date    : April 2011
> Author(s)           : A. Barth
> Category            : PROPOSED STANDARD
> Source              : HTTP State Management Mechanism
> Stream              : IETF
> Verifying Party     : IESG


