@techreport{nir-websec-extended-origin-02, number = {draft-nir-websec-extended-origin-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-nir-websec-extended-origin/02/}, author = {Yoav Nir}, title = {{A More Granular Web Origin Concept}}, pagetotal = 9, year = 2012, month = mar, day = 5, abstract = {This document defines an HTTP header that allows the partitioning of a single origin (as defined in RFC 6454) into multiple origins, so that the same origin policy applies among them. The header introduced in this document allows a portal to specify that resources that appear to be from the same origin should, in fact, be treated as though they are from different origins, by extending the 3-tuple of the origin to a 4-tuple. A compliant user agent is expected to apply the same-origin policy according to the 4-tuple rather than the 3-tuple.}, }