Re: I-D Action: draft-ietf-httpbis-rfc6265bis-01.txt

Mike West <mkwst@google.com> Tue, 25 April 2017 11:07 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8D80512EBCC for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 25 Apr 2017 04:07:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7
X-Spam-Level:
X-Spam-Status: No, score=-7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0NTZEe3zwK5B for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 25 Apr 2017 04:07:38 -0700 (PDT)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A0E2812EBCB for <httpbisa-archive-bis2Juki@lists.ietf.org>; Tue, 25 Apr 2017 04:07:38 -0700 (PDT)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1d2yH7-0005hA-Tv for ietf-http-wg-dist@listhub.w3.org; Tue, 25 Apr 2017 11:04:53 +0000
Resent-Date: Tue, 25 Apr 2017 11:04:53 +0000
Resent-Message-Id: <E1d2yH7-0005hA-Tv@frink.w3.org>
Received: from mimas.w3.org ([128.30.52.79]) by frink.w3.org with esmtps (TLS1.2:RSA_AES_128_CBC_SHA1:128) (Exim 4.80) (envelope-from <mkwst@google.com>) id 1d2yH4-0005gP-KN for ietf-http-wg@listhub.w3.org; Tue, 25 Apr 2017 11:04:50 +0000
Received: from mail-yb0-f172.google.com ([209.85.213.172]) by mimas.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.84_2) (envelope-from <mkwst@google.com>) id 1d2yGx-0000ds-0T for ietf-http-wg@w3.org; Tue, 25 Apr 2017 11:04:45 +0000
Received: by mail-yb0-f172.google.com with SMTP id 8so287816ybw.1 for <ietf-http-wg@w3.org>; Tue, 25 Apr 2017 04:04:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=fi0A+62pA4+1dMzr5FHcT/sVgwHTiidFUqYdzYdRcAI=; b=N06BoP8D2Y1kyUMqPKVfP1Zh6nKYkygjVXlW1pSjngM+YyCS2CmRaadBqQ9Qj8VvWS 0WFxlvBSsAXgkFbyQeRaiiK82uFObDO3vlOXuJohI2ZkhDyTVrnIMCrp6eQvPJJr5Whr RdQoRTgn1fJM7nInZhzK2mjSYKAhSLggRY+Bn5+0njirUrLuRyPmQ5kr5Y/ssapJlEz4 oD+R1z5Crd6HQlj/5BHhOZ/7oXLQU6oJW5MRvy19i3P4cC8iaWA7Xmqa4hPz7ZvKne4b G0cgFSM7r4ecJl0qkymlzDET+FHGtJkvQBeYJ3hTwyQILpAoeS+PN5w7uWrXiuBzknN9 Gz3w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=fi0A+62pA4+1dMzr5FHcT/sVgwHTiidFUqYdzYdRcAI=; b=f6CxkR+blNNbyCZaEb/fECmVLnoWUFfFP6E7EjAVmpXz1hk0fnEPn7kGHJ5IWLEIJl Kz8dS3KQ87omhiYObgGDka+iMk2M4DjUF5pRGJbHo0aPjeKRh4lMCm/z0T6PumlD2drn 58Zgy/rhxZ+RyenrfPmryARkOAkzk4DwfAr4Cg8vnDBM9f92gRjMHydWt9nueIqxXD/M e2sQ8woCpeXBtFPnu/9ipZ8iUlfzKV+siUbNHXfxkqDtSMYjkZIdLbNnJwGbNI+GuYBG 7DoSV727vnHqs5dF+4Q3Bc8Fwz6FxJE1JHSpJR27DHVPjKCU8EYi9LIiWBesgrGuTHbs 561Q==
X-Gm-Message-State: AN3rC/6aDGRF7DykjH3vLrV/8KBL2M+OkV4dssweqGqwb+RXcyIwiMki j8hVlYghVHw8wRnbQw0cDsnMexKc7tp5
X-Received: by 10.37.171.194 with SMTP id v60mr8846128ybi.100.1493118256118; Tue, 25 Apr 2017 04:04:16 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.37.109.65 with HTTP; Tue, 25 Apr 2017 04:03:55 -0700 (PDT)
In-Reply-To: <149311408863.5954.15477072413804974508@ietfa.amsl.com>
References: <149311408863.5954.15477072413804974508@ietfa.amsl.com>
From: Mike West <mkwst@google.com>
Date: Tue, 25 Apr 2017 13:03:55 +0200
Message-ID: <CAKXHy=e6UUd1ogOB9EVbJUcv-9ZyUxcFZecJxemNmCSh5iUSEw@mail.gmail.com>
To: internet-drafts@ietf.org
Cc: i-d-announce@ietf.org, HTTP Working Group <ietf-http-wg@w3.org>
Content-Type: multipart/alternative; boundary="001a11487c5644157f054dfbaf22"
Received-SPF: pass client-ip=209.85.213.172; envelope-from=mkwst@google.com; helo=mail-yb0-f172.google.com
X-W3C-Hub-Spam-Status: No, score=-8.9
X-W3C-Hub-Spam-Report: AWL=2.913, BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_IRR=-3, W3C_WL=-1
X-W3C-Scan-Sig: mimas.w3.org 1d2yGx-0000ds-0T 477502eaad75151dd61196694ff17f09
X-Original-To: ietf-http-wg@w3.org
Subject: Re: I-D Action: draft-ietf-httpbis-rfc6265bis-01.txt
Archived-At: <http://www.w3.org/mid/CAKXHy=e6UUd1ogOB9EVbJUcv-9ZyUxcFZecJxemNmCSh5iUSEw@mail.gmail.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/33837
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

Following up on the discussion at the last meeting, I've revived the
RFC6265bis draft, pulling in both
https://tools.ietf.org/html/draft-ietf-httpbis-cookie-alone-01 and
https://tools.ietf.org/html/draft-ietf-httpbis-cookie-prefixes-00.

https://tools.ietf.org/html/draft-ietf-httpbis-cookie-same-site-00 is going
to take a little bit longer, as I think some pieces of it really need to
live in Fetch as opposed to the RFC. I'll work on that separation, and try
to address the remaining issues
<https://github.com/httpwg/http-extensions/issues?q=is%3Aissue+is%3Aopen+label%3A6265bis>
before the next meeting in July so that we have something concrete to
discuss in that venue.

In any event, now's a good time to file bugs, if you're so inclined. :)

-mike

On Tue, Apr 25, 2017 at 11:54 AM, <internet-drafts@ietf.org> wrote:

>
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories.
> This draft is a work item of the Hypertext Transfer Protocol of the IETF.
>
>         Title           : HTTP State Management Mechanism
>         Authors         : Adam Barth
>                           Mike West
>         Filename        : draft-ietf-httpbis-rfc6265bis-01.txt
>         Pages           : 40
>         Date            : 2017-04-25
>
> Abstract:
>    This document defines the HTTP Cookie and Set-Cookie header fields.
>    These header fields can be used by HTTP servers to store state
>    (called cookies) at HTTP user agents, letting the servers maintain a
>    stateful session over the mostly stateless HTTP protocol.  Although
>    cookies have many historical infelicities that degrade their security
>    and privacy, the Cookie and Set-Cookie header fields are widely used
>    on the Internet.  This document obsoletes RFC 2965.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-httpbis-rfc6265bis/
>
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-httpbis-rfc6265bis-01
> https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-rfc6265bis-01
>
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-httpbis-rfc6265bis-01
>
>
> Please note that it may take a couple of minutes from the time of
> submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
>
>