From: Tay Ray Chuan Date: Tue, 10 Sep 2013 17:07:51 GMT Subject: [PATCH 07/14] weaken specification over cookies for authentication Message-ID: <1378832878-12811-8-git-send-email-rctay89@gmail.com> In-Reply-To: <1378832878-12811-7-git-send-email-rctay89@gmail.com> From: "Shawn O. Pearce" Signed-off-by: Tay Ray Chuan -- To Shawn: sign-off-by needed. Based on the discussion in <20091009195035.GA15153@coredump.intra.peff.net>, <20091015165228.GO10505@spearce.org> (patch), <20091015173902.GA22262@sigill.intra.peff.net> (agreement) From: "Shawn O. Pearce" Message-ID: <20091015165228.GO10505@spearce.org> I weakend the sections on cookies: + Authentication + -------------- .... + Servers SHOULD NOT require HTTP cookies for the purposes of + authentication or access control. and that's all we say on the matter. I took out the Servers MUST NOT line under session state. --- Documentation/technical/http-protocol.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Documentation/technical/http-protocol.txt b/Documentation/technical/http-protocol.txt index 412b898..2382384 100644 --- a/Documentation/technical/http-protocol.txt +++ b/Documentation/technical/http-protocol.txt @@ -52,7 +52,7 @@ Clients SHOULD support Basic authentication as described by RFC 2616. Servers SHOULD support Basic authentication by relying upon the HTTP server placed in front of the Git server software. -Servers MUST NOT require HTTP cookies for the purposes of +Servers SHOULD NOT require HTTP cookies for the purposes of authentication or access control. Clients and servers MAY support other common forms of HTTP based -- 1.8.4.rc4.527.g303b16c