Re: Call for Adoption: draft-reschke-rfc5987bis

"Martin J. Dürst" <duerst@it.aoyama.ac.jp> Tue, 31 March 2015 08:01 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AA9C21B2B25 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 31 Mar 2015 01:01:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.612
X-Spam-Level:
X-Spam-Status: No, score=-6.612 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tjC3bA4aRI8X for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 31 Mar 2015 01:01:28 -0700 (PDT)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3EAFA1B2AF9 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Tue, 31 Mar 2015 01:01:28 -0700 (PDT)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1Ycr3U-0003Pz-5E for ietf-http-wg-dist@listhub.w3.org; Tue, 31 Mar 2015 07:57:48 +0000
Resent-Date: Tue, 31 Mar 2015 07:57:48 +0000
Resent-Message-Id: <E1Ycr3U-0003Pz-5E@frink.w3.org>
Received: from maggie.w3.org ([128.30.52.39]) by frink.w3.org with esmtp (Exim 4.80) (envelope-from <duerst@it.aoyama.ac.jp>) id 1Ycr3K-0003OR-TC for ietf-http-wg@listhub.w3.org; Tue, 31 Mar 2015 07:57:38 +0000
Received: from mail-sg1bn0105.outbound.protection.outlook.com ([134.170.132.105] helo=APAC01-SG1-obe.outbound.protection.outlook.com) by maggie.w3.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.72) (envelope-from <duerst@it.aoyama.ac.jp>) id 1Ycr3J-0006Dg-Ah for ietf-http-wg@w3.org; Tue, 31 Mar 2015 07:57:38 +0000
Received: from [133.2.210.64] (133.2.210.64) by TY1PR01MB0079.jpnprd01.prod.outlook.com (25.161.133.145) with Microsoft SMTP Server (TLS) id 15.1.118.21; Tue, 31 Mar 2015 07:57:07 +0000
Message-ID: <551A534F.5080702@it.aoyama.ac.jp>
Date: Tue, 31 Mar 2015 16:57:03 +0900
From: "\"Martin J. Dürst\"" <duerst@it.aoyama.ac.jp>
Organization: Aoyama Gakuin University
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: Willy Tarreau <w@1wt.eu>, Mark Nottingham <mnot@mnot.net>
CC: HTTP Working Group <ietf-http-wg@w3.org>
References: <1C7436D4-D1EF-454C-BC14-E8C00165AA2E@mnot.net> <20150331054245.GB7069@1wt.eu>
In-Reply-To: <20150331054245.GB7069@1wt.eu>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Originating-IP: [133.2.210.64]
X-ClientProxiedBy: OS1PR01CA0016.jpnprd01.prod.outlook.com (25.161.225.154) To TY1PR01MB0079.jpnprd01.prod.outlook.com (25.161.133.145)
Authentication-Results: w3.org; dkim=none (message not signed) header.d=none;
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:TY1PR01MB0079;
X-Microsoft-Antispam-PRVS: <TY1PR01MB0079ED669506244E764C0D07CAF40@TY1PR01MB0079.jpnprd01.prod.outlook.com>
X-Forefront-Antispam-Report: BMV:1; SFV:NSPM; SFS:(10019020)(6009001)(6049001)(479174004)(24454002)(2950100001)(50466002)(77156002)(50986999)(54356999)(65816999)(33656002)(83506001)(47776003)(87266999)(62966003)(76176999)(85182001)(87976001)(66066001)(92566002)(23676002)(42186005)(86362001)(74482002)(46102003)(80316001)(230783001)(85202003)(122386002)(40100003)(65956001)(3940600001)(781001); DIR:OUT; SFP:1102; SCL:1; SRVR:TY1PR01MB0079; H:[133.2.210.64]; FPR:; SPF:None; MLV:sfv; LANG:en;
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(5005006)(5002010); SRVR:TY1PR01MB0079; BCL:0; PCL:0; RULEID:; SRVR:TY1PR01MB0079;
X-Forefront-PRVS: 0532BF6DC2
X-OriginatorOrg: it.aoyama.ac.jp
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 31 Mar 2015 07:57:07.9588 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: TY1PR01MB0079
Received-SPF: pass client-ip=134.170.132.105; envelope-from=duerst@it.aoyama.ac.jp; helo=APAC01-SG1-obe.outbound.protection.outlook.com
X-W3C-Hub-Spam-Status: No, score=-6.9
X-W3C-Hub-Spam-Report: AWL=0.096, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_IRR=-3, W3C_WL=-1
X-W3C-Scan-Sig: maggie.w3.org 1Ycr3J-0006Dg-Ah 48ea50fdbaeb82682c31b81b078d2867
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Call for Adoption: draft-reschke-rfc5987bis
Archived-At: <http://www.w3.org/mid/551A534F.5080702@it.aoyama.ac.jp>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/29114
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

On 2015/03/31 14:42, Willy Tarreau wrote:
> Also, I'd prefer to make it explicitly forbidden to %-encode US-ASCII
> characters because this could be used to bypass some WAFs for example :
> if it is detected that a server implements this standard and is able
> to %-decode some attributes in header fields, and a WAF in the middle
> does not, the client can abuse the %-encoding to try to hide some
> activities.

This makes a lot of sense, but we have to be careful that this doesn't 
apply to all US-ASCII characters; there will be some that have to be 
escaped because of syntactic constraints.

<rant>
It's really a pitty that more than 25 years after the first version of 
HTTP, we are still carrying around this kind of antiquated baggage.
</rant>

I see that UTF-8 is the only encoding that's a MUST in the draft, so at 
least that's progress in the right direction (although rather glacial).

Regards,   Martin.