This Internet-Draft is no longer active. Unofficial copies of old Internet-Drafts can be found here:
http://tools.ietf.org/id/draft-ietf-websec-origin.
Abstract:
This document defines the concept of an "origin", which is often used as
the scope of authority or privilege by user agents. Typically, user agents isolate content retrieved from different
origins to prevent malicious web site operators from interfering with the operation of benign web sites. In
addition to outlining the principles that underlie the concept of origin, this document details how to determine
the origin of a URI and how to serialize an origin into a string. It also defines
an HTTP header field, named "Origin", that indicates which origins are associated
with an HTTP request. [STANDARDS-TRACK]
Authors:
Adam Barth <ietf@adambarth.com>
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid)