Re: [hybi] Comments about draft-13

Iñaki Baz Castillo <ibc@aliax.net> Tue, 06 September 2011 18:02 UTC

Return-Path: <ibc@aliax.net>
X-Original-To: hybi@ietfa.amsl.com
Delivered-To: hybi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B6E1A21F8B28 for <hybi@ietfa.amsl.com>; Tue, 6 Sep 2011 11:02:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.647
X-Spam-Level:
X-Spam-Status: No, score=-2.647 tagged_above=-999 required=5 tests=[AWL=0.030, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DBKKDz6t2bad for <hybi@ietfa.amsl.com>; Tue, 6 Sep 2011 11:02:35 -0700 (PDT)
Received: from mail-qw0-f52.google.com (mail-qw0-f52.google.com [209.85.216.52]) by ietfa.amsl.com (Postfix) with ESMTP id 3448D21F8AB8 for <hybi@ietf.org>; Tue, 6 Sep 2011 11:02:35 -0700 (PDT)
Received: by qwb8 with SMTP id 8so5668515qwb.25 for <hybi@ietf.org>; Tue, 06 Sep 2011 11:04:22 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.229.221.21 with SMTP id ia21mr1056390qcb.253.1315332261777; Tue, 06 Sep 2011 11:04:21 -0700 (PDT)
Received: by 10.229.79.207 with HTTP; Tue, 6 Sep 2011 11:04:21 -0700 (PDT)
In-Reply-To: <F54EFBF4-57D2-4425-AAB3-DB6DA5F8DB61@bbn.com>
References: <CALiegfkUMDfuRC+16ZcLo__2OqAcQ1UVDGa_610ykEAe6yZViw@mail.gmail.com> <CALiegf=wO6w5UMLO-hsn8o0cX3__SuxMDrgqvScuS6QWdNhptw@mail.gmail.com> <A59BAA80-CD38-48C4-A113-C1493072D079@bbn.com> <CALiegfnru1MDVLZAQW9cxrR4D=Wfu+MAEzn0BHfSu_v31ztvrg@mail.gmail.com> <CALiegfnjXqggJhZG2YHSAQLK+uPXTxyKo3N=K4qE6OdjwieNtg@mail.gmail.com> <AADB2126-0259-4636-88D8-78D8B5E69EE6@bbn.com> <CALiegfmS5KmooZ57+XWJtks2fHxw=8tCnm4oRMa2JtOM8DJR7g@mail.gmail.com> <F54EFBF4-57D2-4425-AAB3-DB6DA5F8DB61@bbn.com>
Date: Tue, 06 Sep 2011 20:04:21 +0200
Message-ID: <CALiegfkNoT5nbb_MXKfW4dv-8n1PZa_aXLEMUbsVix-VnB=NFA@mail.gmail.com>
From: Iñaki Baz Castillo <ibc@aliax.net>
To: "Richard L. Barnes" <rbarnes@bbn.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Cc: hybi@ietf.org
Subject: Re: [hybi] Comments about draft-13
X-BeenThere: hybi@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Server-Initiated HTTP <hybi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/hybi>, <mailto:hybi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/hybi>
List-Post: <mailto:hybi@ietf.org>
List-Help: <mailto:hybi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/hybi>, <mailto:hybi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Sep 2011 18:02:35 -0000

2011/9/6 Richard L. Barnes <rbarnes@bbn.com>:
> Correct.  So absent further restrictions in the API, a script could supply arbitrary UTF-8 data.  Thus, non "Sec".

Sure? At least Chrome 15.X does not allow me to set a WS subprotocol
called "foo.€áéíóúñ.com". It does not send the HTTP GET request and
logs an error:

  Wrong protocol for WebSocket
'foo.\u20AC\u00E1\u00E9\u00ED\u00F3\u00FA\u00F1.com'

-- 
Iñaki Baz Castillo
<ibc@aliax.net>