a Secarta project ...

HTTPsec Authentication Protocol


Preamble

4.4. url

The url directive in an initialization request and a continuation request is the the absolute URL of that request. The latter is duplicated in this directive because proxies are legitimately allowed to change the Request-Line in transit.

The responder MUST confirm that the value of this directive is equivalent to the absolute URL implied by the request's Request-Line [HTTP] and Host [HTTP] header. Equivalence conditions for URLs are given in [URI] Section 6.