OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

 


 

   RE: [xml-dev] Re: Cookies at XML Europe 2004 -- Call for Particip ation

[ Lists Home | Date Index | Thread Index ]

> The real problem is that cookies are completely contrary to the web
> architecture.

Nonsense.  A cookie holding authentication credentials is conceptually
the same as content negotatiation, one of the REST principles.

> Even if there were no privacy implications,
> cookies would still be the wrong solution.

Since you seem to have given this more than just casual thought, have
you got ideas about a solution?  To be explicit, the goals are:
        Authenticate clients
        Allow URL's to be cut/pasted amonng participants
        Limited exposure if packets are snooped

--
Rich Salz                  Chief Security Architect
DataPower Technology       http://www.datapower.com
XS40 XML Security Gateway  http://www.datapower.com/products/xs40.html
XML Security Overview      http://www.datapower.com/xmldev/xmlsecurity.html





 

News | XML in Industry | Calendar | XML Registry
Marketplace | Resources | MyXML.org | Sponsors | Privacy Statement

Copyright 2001 XML.org. This site is hosted by OASIS