<?xml version='1.0' encoding='UTF-8'?>

<reference anchor='I-D.abarth-origin'>
<front>
<title>The HTTP Origin Header</title>

<author initials='A' surname='Barth' fullname='Adam Barth'>
    <organization />
</author>

<author initials='C' surname='Jackson' fullname='Collin Jackson'>
    <organization />
</author>

<author initials='I' surname='Hickson' fullname='Ian Hickson'>
    <organization />
</author>

<date month='September' day='29' year='2009' />

<abstract><t>This document defines the HTTP Origin header.  The Origin header is added by the user agent to describe the security contexts that caused the user agent to initiate an HTTP request.  HTTP servers can use the Origin header to mitigate against Cross-Site Request Forgery (CSRF) vulnerabilities.</t></abstract>

</front>

<seriesInfo name='Internet-Draft' value='draft-abarth-origin-05' />
<format type='TXT'
        target='http://www.ietf.org/internet-drafts/draft-abarth-origin-05.txt' />
</reference>
