 Cookies: HTTP State Management Mechanism
 Date: 21/07/2024
 Authors: Steven Bingler, Mike West, John Wilander
 Working Group: HTTP (httpbis)
This document defines the HTTP Cookie and Set-Cookie header fields. These header fields can be used by HTTP servers to store state (called cookies) at HTTP user agents, letting the servers maintain a stateful session over the mostly stateless HTTP protocol. Although cookies have many historical infelicities that degrade their security and privacy, the Cookie and Set-Cookie header fields are widely used on the Internet. This document obsoletes RFC 6265.
 The HTTP QUERY Method
 Date: 21/10/2024
 Authors: Julian Reschke, Ashok Malhotra, James Snell, Mike Bishop
 Working Group: HTTP (httpbis)
This specification defines a new HTTP method, QUERY, as a safe, idempotent request method that can carry request content.
 Resumable Uploads for HTTP
 Date: 21/10/2024
 Authors: Marius Kleidl, Guoye Zhang, Lucas Pardue
 Working Group: HTTP (httpbis)
HTTP clients often encounter interrupted data transfers as a result of canceled requests or dropped connections. Prior to interruption, part of a representation may have been exchanged. To complete the data transfer of the entire representation, it is often desirable to issue subsequent requests that transfer only the remainder of the representation. HTTP range requests support this concept of resumable downloads from server to client. This document describes a mechanism that supports resumable uploads from client to server using HTTP.
 The Concealed HTTP Authentication Scheme
 Date: 19/09/2024
 Authors: David Schinazi, David Oliver, Jonathan Hoyland
 Working Group: HTTP (httpbis)
Most HTTP authentication schemes are probeable in the sense that it is possible for an unauthenticated client to probe whether an origin serves resources that require authentication. It is possible for an origin to hide the fact that it requires authentication by not generating Unauthorized status codes, however that only works with non-cryptographic authentication schemes: cryptographic signatures require a fresh nonce to be signed. Prior to this document, there was no existing way for the origin to share such a nonce without exposing the fact that it serves resources that require authentication. This document defines a new non-probeable cryptographic authentication scheme.
 Template-Driven HTTP CONNECT Proxying for TCP
 Date: 21/10/2024
 Authors: Benjamin Schwartz
 Working Group: HTTP (httpbis)
TCP proxying using HTTP CONNECT has long been part of the core HTTP specification. However, this proxying functionality has several important deficiencies in modern HTTP environments. This specification defines an alternative HTTP proxy service configuration for TCP connections. This configuration is described by a URI Template, similar to the CONNECT-UDP and CONNECT-IP protocols.
 Compression Dictionary Transport
 Date: 28/08/2024
 Authors: Patrick Meenan, Yoav Weiss
 Working Group: HTTP (httpbis)
This document specifies a mechanism for dictionary-based compression in the Hypertext Transfer Protocol (HTTP). By utilizing this technique, clients and servers can reduce the size of transmitted data, leading to improved performance and reduced bandwidth consumption. This document extends existing HTTP compression methods and provides guidelines for the delivery and use of compression dictionaries within the HTTP protocol.
 HTTP Cache Groups
 Date: 17/06/2024
 Authors: Mark Nottingham
 Working Group: HTTP (httpbis)
This specification introduces a means of describing the relationships between stored responses in HTTP caches, "grouping" them by associating a stored response with one or more opaque strings.
 Secondary Certificate Authentication of HTTP Servers
 Date: 12/10/2024
 Authors: Eric Gorbaty, Mike Bishop
 Working Group: HTTP (httpbis)
This document defines a way for HTTP/2 and HTTP/3 servers to send additional certificate-based credentials after a TLS connection is established, based on TLS Exported Authenticators.
 Security Considerations for Optimistic Protocol Transitions in HTTP/1.1
 Date: 21/10/2024
 Authors: Benjamin Schwartz
 Working Group: HTTP (httpbis)
In HTTP/1.1, the client can request a change to a new protocol on the existing connection. This document discusses the security considerations that apply to data sent by the client before this request is confirmed, and updates RFC 9298 to avoid related security issues.
 Date: 27/09/2024
 Authors: Domenic Denicola, Jeremy Roman
 Working Group: HTTP (httpbis)
A proposed HTTP header field for changing how URL search parameters impact caching.


