Next in thread → Next in month →

RE: [security-services] FW: Comments on Bindings and Profiles doc - Draft 06

From
John Hughes <>
Date
2003-05-20T16:19:11+00:00
ID
Thread
RE: [security-services] FW: Comments on Bindings and Profiles doc - Draft 06
Scott,

I understand the processing - the HTML form has the TARGET value within - so
that when the POST occurs that value will be available to the receiving web
application.  The web application could then use that value to do a redirect
etc to the actual target.  My only point is that this is not explained at
all - and I believe it should do - accepting of course that it is
non-normative.

John



> -----Original Message-----
> From: Scott Cantor [mailto:]
> Sent: 20 May 2003 17:15
> To: 'John Hughes'; 
> Subject: RE: [security-services] FW: Comments on Bindings and Profiles
> doc - Draft 06
>
>
> > Also some comments on the Browser/POST Profile section:
> >
> > General - seems strange to the reader that the TARGET value
> > supplied in the HTML form received back is then not used in
> > the POST.  I think something should be said on this matter.
>
> Used in what sense? Normally it gets used to redirect the browser
> to the resource, but since the profile doesn't formally require
> TARGET be used in that way, it doesn't mandate anything.
>
> -- Scott
Next in thread → Next in month →