It makes me smile when someone raves about how fast this website loads, because that's no accident. We put a lot of effort into making it so. It is the sort of thing that usually goes unnoticed, but when your readers are developers, there's a better chance they notice and appreciate it. I have written about this in the past, but it's worth re-examining because these ideas are always evolving. From
Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article? ã¯ããã« å»å¹´ãããããCookieã«é¢ããè°è«ãæ´»çºã«è¡ãªããã¦ããããã«æãã¾ããããã§Cookieé¢é£ã®ææ°ååã«ã¤ãã¦ä»æ§ã®è¦³ç¹ããå¹¾ã¤ãåæãã¾ãã Deprecate modification of 'secure' cookies from non-secure origins Cookie Prefixes Same-site Cookies A Retention Priority Attribute for HTTP Cookies Content Security Policy: Cookie Controls G
çµäº 2015/10/15ï¼æ¨ï¼ 19:00ã ãã°åæåå¼·ä¼ vol.1 ã»ãã¥ãªãã£ã®é£ kenji kobayashi ä» æ±äº¬é½å代ç°åºå¹³æ²³çº2-16-1 平河çºæ£®ã¿ã¯ã¼2F
Webã»ãã¥ãªãã£ãèããä¸ã§å¤§äºãªä»çµã¿ã®ä¸ã¤ã«ãSame-Origin Policyã¨ããä»çµã¿ãããã¾ãã Originã¯ãã¹ãã¼ã ã»ãã¹ãã»ãã¼ããã®çµã¿åããã§ããããããä¸ç·ã§ããã°ãåä¸Originã§ãããªã½ã¼ã¹ã¸ã¢ã¯ã»ã¹ãããã¨ãã§ãã¾ãã æ´å²ççµç·¯ãæ§ã ãªçç±ã«ããè¤æ°ã®ã¢ããªã±ã¼ã·ã§ã³ãåä¸Originã§æä¾ããã¦ããå ´åãããã¾ãã ãã¨ãã°ã"ãã£ãã"ã"ã·ã§ããã³ã°"ã®æ©è½ã以ä¸ã®æ§ãªURLã§æä¾ããã¦ãããããªå ´åã§ãã https://example.com/chat/ https://example.com/shopping/ å®éãGoogleã®æ¤ç´¢ãµã¼ãã¹ã¨å°å³ãµã¼ãã¹ã¯åä¸Originã§æä¾ããã¦ãã¾ããæãããããªã³ã¯ããããã©ã¼ãã³ã¹ããã©ã³ãã£ã³ã°ã®ããã®ããã§ãã https://www.google.com https://www.goo
2023å¹´03æ31æ¥è¿½è¨ï¼ãã®è¨äºãåºã«ã@sadnessOjisanãããããã³ã¼ãã¬ãã«ã«ããè¸ã¿è¾¼ãã ããã¤ãã°ãªã¼ã³ã¹ã¬ãããã¼ã¹ã®æ°ããWebãµã¼ãã¢ã¼ããã¯ãã£ãå«ãã¦æ´çãããè¨äº Webãµã¼ãã¼ã¢ã¼ããã¯ãã£é²åè«2023 | blog.ojisan.io ãå ¬éããã¾ããã 主ã«æ°åã®Webã¨ã³ã¸ãã¢åãã«ãå¤å ¸çãªWebãµã¼ãã¢ã¼ããã¯ãã£ãå¦ã¶éã®ãã¨ä»£è¡¨çãªå®è£ ã¢ãã«ã®æ¦è¦ãç´¹ä»ãã¾ãã ãã®è¾ºãã®è©±é¡ãWebçéã§æµè¡ã£ã¦ããã®ã¯æ°å¹´ä»¥ä¸åã¨ããã¤ã¡ã¼ã¸ã§ãããWebãµã¼ãã¹ã¯ç¸å¤ãããWebãµã¼ãã®ä¸ã§åãã¦ããã®ã§ãæµè¡ãå»ãé¢ä¿ãªãå¦ã¶ã¹ãå 容ã ã¨æã£ã¦ãã¾ãã ã¾ããHTTP/2ãããããRFCåããæ¢ã«h2oãtrusterdãªã©ã®HTTP/2ã®ãµã¼ãå®è£ ããããä»å¾Webãµã¼ãã¢ã¼ããã¯ãã£ãå訪ãããã¨ãå¢ãããããªæ°ããã¦ãã¾ãã ã¨ããããWe
WebAPIã®ä»æ§ãè¨è¿°ããæ¹æ³ã¯ããã¤ãããã¨æãã æ®éã«æ¥æ¬èªã§è¨è¿°ãã JSON Hyper-SchemaãWADLãRAMLãSwaggerãªã©ã使ã ä»æ§æ¸ã®ä»£ããã«ããã°ã©ã ãæ¸ã HTTPã¡ãã»ã¼ã¸ãã®ãã®ãè¨è¿°ãã¦ãã ã§ããææ³ã«ã°ãã¤ãããã£ãããèªã¿ã«ããã£ããããã¼ã«ã®ã»ããã¢ãããé¢åã ã£ãããã©ããã¤ãã¤ããªæããã£ã¦ãæ軽ãªæ¹æ³ã欲ããã¨æã£ã¦ããã ä½æ°ãªãcurlã³ãã³ãã®ãªãã·ã§ã³ã調ã¹ã¦ãããããããããã§APIããã¥ã¡ã³ãæ±ãã«ãã¡ããã°ããããããï¼ãã¨æãã¦ããã®ã§ã¡ã¢ãã¦ããã curlã³ãã³ãã®ãããã curlã³ãã³ãã¯libcurlã®ä»å±ã³ãã³ãã§ãæè¿ã®Unixç³»OSãªã大æµæåããå ¥ã£ã¦ããã¨æããã³ãã³ãã®è©³ç´°ã¯manãèªãã§ããã ããã°ã cURL - How To Use ï¼ããã¥ã¢ã«ãã¼ã¸æ¥æ¬èªè¨³ï¼ curlã³ãã³ãã®ãªãã·
This document defines a mechanism which allows authors to instruct a user agent to upgrade a priori insecure resource requests to secure transport before fetching them. This is a public copy of the editorsâ draft. It is provided for discussion only and may change at any moment. Its publication here does not imply endorsement of its contents by W3C. Donât cite this document other than as work in pr
Private content!This content has been marked as private by the uploader.
Web based on Standards Web ã¯èª°ã®ãã®ã§ãããã¾ããã ã ãããããã¯ããªã¼ãã¼ããã¦ãã®äººãææ決å®ããã¨ããããããã®ã¨ã¯çéã®æãç«ã¡ããã¦ãã¾ãã æ¨æºçãªä»æ§ã決ãã¦ããã®ä»æ§ã«åã£ã¦ Web ã®ä¸çã¯æãç«ã£ã¦ããã æ¿åºãä½ããµã¤ããã Twitter ããå¦çãä½ã£ãããã°ããå ¨é¨åãã«ã¼ã«ã§ä½ããã¦ãããã ããç¹ããã ããã£ã¦çµæ§åããã¨ã ã¨ãèªåã¯æã£ã¦ãã¾ãã Standarization ãã®ã«ã¼ã«ã®æ±ºãæ¹ã«ãã«ã¼ã«ããã£ã¦ãã¡ãã£ã¨æ·å± ã¯é«ããããããªããã©ã誰ã§ãèªç±ã«åå ãã¦ãèªç±ã«æè¦ãè¿°ã¹ããã¨ãã§ããå ´ãããã¾ãã æ¨æºåå£ä½ã£ã¦ãã¤ã§ããã ãªããä¸é¨ã®äººãã¡ãåæã«ãã£ã¦ããããã«æãããããããªããã©ãããã¯é¸æã«è¡ããªã人ã®çè«ã¨åãã§ãã ããªããä»æ§ã«ã¤ãã¦æè¦ãæã£ã¦ã¦ãããã妥å½ã§ãããªãã°ããã®çºè¨ã¯ä»æ§ãæ ¹
â HTTPã§HashãArrayãéãææ³ã«ä»æ§ã¯åå¨ããªãâ¦â¦ã®? jQueryã§ãããªãµãã«æ¸ãã¨: $.post('/', { hash: { foo: 'hoge', bar: 'fuga'}, array: ['baz', 'piyo'] }); ãµã¼ãå´ã§ãããªãµãã«åãåãã¦(ããã¯Sinatra): post '/' do params.each do |key, val| puts "#{key}: #{val} as #{val.class}" end end ã¡ããã¨HashãArrayã¨ãã¦ã¢ã¯ã»ã¹ã§ãã: hash: {"foo"=>"hoge", "bar"=>"fuga"} as Hash array: ["baz", "piyo"] as Array ããããã便å©ã ããã§æ¸ã¾ãã¦ããããã ãã©ãHTTP POSTã®ä¸èº«ãªãã¦ãã ã®ãã¤ãåãªãã ããåã®æ
å®å ¨ã«é£ãã¿ã¤ãã«ã§ããã©ä¸èº«ã¯çé¢ç®ã«æ¸ããã è¿å¹´ãã¦ã§ããµã¤ãã®HTTPSåãæµè¡ã®ããã«ãªã£ã¦ãããç§ã®ç¥ãéããGoogleã®å種ãµã¼ãã¹ãTwitterãFacebookãªã©ãå®å ¨ã«HTTPSã§éä¿¡ãè¡ãããã«ãªã£ã¦ãããHTTPSãã¤ã¾ãSSLã«ããéä¿¡ã®æå·åã«ãã£ã¦ãã¦ã¼ã¶ã«ããã¾ã§ãããå®å ¨ãªã¦ã§ããµã¤ããæä¾ã§ããã ããããããªããä½ã£ã¦ãããµã¤ãããµã¨æãã¤ãã§HTTPSåãã¦ãã¾ãã¨ããã¶ããããã¾ã§ããããµã¤ããé ããªããããã§ã¯ãHTTPSã§éä¿¡ããå ´åã®åé¡ã解説ããã ãªãé ããªãã®ã HTTPã§éä¿¡ããå ´åãã¯ã©ã¤ã¢ã³ãããµã¼ãã¸ã¨æ¥ç¶ããããã«ã¯TCP/IPã®3ã¦ã§ã¤ãã³ãã·ã§ã¤ã¯ã¨ããæé ãå¿ è¦ã«ãªããããã©ãããã®ã§ããã§ã¯è©³ããã¯èª¬æããªãããè¦ããã«ã¯ã©ã¤ã¢ã³ãããªã¯ã¨ã¹ããæããåã«ãã±ãããï¼å¾å¾©ãããªãã¨ãããªãã®ã§ããããã±ããã®å¾å¾©
TAG Finding 01 December 2011This version: http://www.w3.org/2001/tag/doc/IdentifyingApplicationState-20111201 Latest version: http://www.w3.org/2001/tag/doc/IdentifyingApplicationState Previous versions: http://www.w3.org/2001/tag/doc/IdentifyingApplicationState-20111130 http://www.w3.org/2001/tag/doc/IdentifyingApplicationState-20110930 http://www.w3.org/2001/tag/doc/IdentifyingApplicationState-2
Translation of: Adding meaning to your HTTP error pages! by Stuart Colville This article is licensed under a Creative Commons Attribution, Non Commercial - Share Alike 2.5 license ã¯ããã« ã¦ã§ãä¸ã§ä½ããæ¤ç´¢ãããã¨ããã¨ãæ¢ã«åå¨ããªããã¼ã¸ããæ¤ç´¢çµæã«ãªãããããã¸ã®ãªã³ã¯ãã¯ãªãã¯ãããã¨ã¯ããããã ããããã®éãããã¼ã¸ã«ããã©ã«ãã®ã¨ã©ã¼ã»ã¡ãã»ã¼ã¸ã®ä»ã«ä½ãæ å ±ãè¼ã£ã¦ããªãã£ãå ´åãå¤ãã®äººã ã¯æ»ããã¿ã³ãæ¼ã次ã®æ¤ç´¢çµæãéããã¨ããã ããã ãµã¤ã製ä½è ã§ããæã ã¯ãã£ã¨è¨ªåè ã«æå³ã®ããã¨ã©ã¼ãã¼ã¸ãä½æãããã¨ãã§ãããããããã°ãã¨ãã¨ã©ã¼ãã¼ã¸ã§ãã£ã¦ã訪åè ããµã¤ãã«çã¾ãããå½¼ã
æ¦è¦ Cookie ã®ä¸å¹¸ãªæ´å²ã¨ç¾ç¶ãããã¦å°æ¥ã«ã¤ãã¦ã¾ã¨ããã ä»æ§ã¯ã©ãã«ããã Web ä¸ã®æ§ã ãªè¦æ ¼ã¯ã誰ããå®ããããã«çãåãããã¨ããå½¢ã§åãã¦ãããããããCookie ã®ä»æ§ã¯èª°ã決ããã©ãã§è¦å®ããã¦ãããç¥ã£ã¦ãã人ã¯ãæå¤ã¨å°ãªãã®ã§ã¯ãªããã¨æããW3C ã IETF ã ã¨æã£ã¦ãã人ãå¤ãã®ã§ã¯ãªããããã æ£è§£ãè¨ã£ã¦ãã¾ãã¨ãå®ããã®ã¯ 1994 å¹´ãNetscape Communications 社ã§ãããææ¸ã¯ http://wp.netscape.com/newsref/std/cookie_spec.html ã§å ¬éããã¦ãããã¢ã¯ã»ã¹ãã¦ã¿ãã°ãããéãããã®ãã¼ã¸ã¯ããåå¨ããªãããNetscape 社èªä½ã AOL ã«è²·åããã¦ãããä»ã¯ Mozilla ã«ãªã£ãã¨ããããæ¶ãã¦ãªããªã£ã¦ãããã¨ãç¥ã£ã¦ãã人ã¯å¤ãã ãããå½æã®ææ¸ã¯ä¾ã«
POSTãããã¼ã¿ããï¼ãã¬ãã¥ã¼ã®ããã«ï¼javascriptã§GETã¢ã¯ã»ã¹ãããããªå¦çãæ¸ãã¦ãã¦ããã£ã話ã çºç«¯ã¯ãtextareaã«'ï¼ã·ã³ã°ã«ã¯ãªã¼ãã¾ãã¯ã¢ãã¹ãããã£ã¼ï¼ãå ¥ãã¨ãRailsãããããå ã®ãã©ã¡ã¼ã¿ã¼ãç¡è¦ãã¡ããã£ã¦ãããã¨ããããã調ã¹ãçµæã以ä¸ã®ãã¨ãããã£ãï¼Railsã®ãã¼ã¸ã§ã³ã¯2.0.2ï¼ã URIãå®ç¾©ããï¼ã¤ã®RFC URIã®æ§æã¯RFCã§å®ç¾©ããã¦ãããããã«ã¯2ã¤ãã£ã¦ãå¾æ¥ã®RFC2396ï¼1998å¹´çºè¡ï¼ã¨ãRFC3986ï¼2005å¹´çºè¡ï¼ã ã RFC3986ã«ããã°ã This document obsoletes [RFC2396], which merged "Uniform Resource Locators" [RFC1738] and "Relative Uniform Resource Locators" [RF
ããã«ã¡ã¯ãSEã®é²å°ã§ãã XSSï¼Cross Site Scriptingï¼èå¼±æ§ã®ä¸ã§ãã¾ã注æãæããã¦ããªãã¿ã¤ãã«DOM Based XSSã¨ãããã®ãããã¾ããã¢ãã¦ã³ã¹èªä½ã¯éåã¨æããè¡ããã¦ãããwebappsec.orgã§ã2005/7/4ã«Amit Kleinæ°ã"DOM Based Cross Site Scripting or XSS of the Third Kind"ãçºè¡¨ãã¦ãã¾ãã Web 2.0çã¢ããªãªã©ã§ã®Ajaxã®æ®åã§JavaScriptãå¤ç¨ãããç¾å¨ã®Webéçºã§ã¯ãDOM Based XSSãå ¥ãè¾¼ãå¯è½æ§ã¯å¾æ¥ãããé«ã¾ã£ã¦ãã¾ããããã§ãä»åã¯ãã®DOM Based XSSã«ã¤ãã¦èª¬æãããã¨æãã¾ãã DOM Based XSSã¨ã¯ä½ãï¼ ä¸è¬çã«XSSèå¼±æ§ã¨èãã¦æãæµ®ãã¹ãã®ã¯ãæ»æè ã®æªæããå ¥åãã¼ã¿ï¼JavaScript
èªåãä»ä½åã®æ¬ãæã£ã¦ããã®ãããããªããªã£ã¦ä¹ ããï¼ç¬ï¼ãæ¬ã¨ããã¢ãã¯ãã£ãã«ã¨ã£ã¦ã¯ä¸æä¸ä¼æãå¼·ããæãç«ã£ãã¨ãã«è²·ããªãã¨è²·ãéãã¦ãã¾ããã¨ããç¦ãã®ãããªãã®ãããã好ããªã¸ã£ã³ã«ãSFããã¹ããªã¼ããµãã«ã¼ãæ ç»ã¨ãããã¨ããããç¹ã«SFã¯å ¥æå°é£ã«ãªãçãé«ãããã«æããé»åæ¸ç±ã«ãªã£ã¦ããã°ããªã延å½ã§ãããã好ããªã¸ã£ã³ã«ã«ã¤ãã¦ã¯ãã¯ãç´ã®æ¬ãè¯ãã ã¾ãè¿å¹´ãæãã¨ãããããé¢å¿ã®å¹ ãæ¡ãã¦ããã®ã§ãå¿ ç¶çã«è²·ãæ¬ã®éã¯å¢ãã¦ããããã¨ãããµã¤ãã¼ã»ãã¥ãªãã£é åã¯å°éã ã£ãã®ã§ä½ããè²·ããã¨ã«ãã¦ããããããã«å ãã¦åºãITã«é¢ããæè¡æ¸ãå¨è¾ºã«æ¡ãããããªå½¢ã§è²·ã£ã¦ãããæ°çã¢ãã«é¢é£ãæ°æè¡ã«é¢ããæ¬ãå¢ãã¦ããããè¥æ人æè²æã«çµ¡ãã¦ããããã³ã³ãã³ãå¶ä½ã®ããã«ã©ã¤ãããã«ã«ã¾ã§æãåºãã¦ãã¦ä¸æã¯ã¨ãã§ããªããã¨ã«ãªã£ã¦ããããããªãæ°é¢å¿é åã¨ã
ã©ã³ãã³ã°
ãç¥ãã
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}