Re: Concern about status code 303 and resolution to Rec33

Mark Baker <[email protected]>
Newsgroups gmane.text.xml.distributed
Message-ID <[email protected]>
Noah,

On 12/7/05, [email protected] <[email protected]> wrote:
> Mark Baker writes:
>
> > Unfortunately it's not the role of the service to declare that
> > it can be trusted 8-); that's something only the human
> > operating the client can decide, because they - not the service
> > doing the redirection - have to take responsibility for the
> > implications of the unsafe message....  hence the need to
> > verify with them.
>
> I dont' think it's directly the service that says "trust my redirections",

Right, but that's what I interpreted Yves to be saying when he wrote;

] However, if you have a description of a service that explicitely says
] "you might get redirected to this set of URIs, and **it is OK**"
(emphasis mine)

> it's the human who chooses to install "client" software that's configured
> to say "if you get a redirect that matches [your favorite predicate
> involving ports, endpointrefs, QNames, whatever], then assume that
> redirections are to be trusted. If the human chooses to base that
> predicate on a reading of the "instruction book" for some particular
> service, so be it.  That's his or her choice.  I think the intent of the
> proposed spec text is fine as it stands.

Agreed.

Mark
--
Mark Baker.  Ottawa, Ontario, CANADA.       http://www.markbaker.ca
Coactus; Web-inspired integration strategies  http://www.coactus.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.