<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.39 (Ruby 3.2.2) -->
<?rfc-ext html-pretty-print="prettyprint https://cdn.rawgit.com/google/code-prettify/master/loader/run_prettify.js"?>
<rfc xmlns:x="http://purl.org/net/xml2rfc/ext"
     category="std"
     consensus="true"
     docName="draft-ietf-httpbis-no-vary-search-09"
     ipr="trust200902"
     sortRefs="true"
     submissionType="IETF"
     symRefs="true"
     tocInclude="true"
     version="3">
   <x:feedback template="mailto:ietf-http-wg@w3.org?subject={docname},%20%22{section}%22\&amp;amp;body=%3c{ref}%3e:"/>
   <!-- xml2rfc v2v3 conversion 3.34.0 -->
   <front xmlns:xi="http://www.w3.org/2001/XInclude">
      <title abbrev="No-Vary-Search">The No-Vary-Search HTTP Caching Extension</title>
      <seriesInfo name="Internet-Draft" value="draft-ietf-httpbis-no-vary-search-09"/>
      <author fullname="Domenic Denicola">
         <organization>Google LLC</organization>
         <address>
            <email>d@domenic.me</email>
         </address>
      </author>
      <author fullname="Jeremy Roman">
         <organization>Google LLC</organization>
         <address>
            <email>jbroman@chromium.org</email>
         </address>
      </author>
      <author fullname="Nidhi Jaju" role="editor">
         <organization>Google LLC</organization>
         <address>
            <email>nidhijaju@chromium.org</email>
         </address>
      </author>
      <date day="17" month="August" year="2026"/>
      <area>Web and Internet Transport</area>
      <workgroup>HyperText Transfer Protocol</workgroup>
      <keyword>http</keyword>
      <keyword>caching</keyword>
      <abstract><?line 108?>
         <t>This specification defines an extension to HTTP Caching, changing how the URI query component impacts caching. It introduces the <tt>"No-Vary-Search"</tt> response header field, which allows origin servers to signal to caches that certain parts of the query component do not semantically affect the served response and can be ignored for cache matching purposes.</t>
      </abstract>
      <note removeInRFC="true">
         <name>About This Document</name>
         <t>The latest revision of this draft can be found at <eref target="https://httpwg.org/http-extensions/draft-ietf-httpbis-no-vary-search.html"/>. Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-ietf-httpbis-no-vary-search/"/>.</t>
         <t>Discussion of this document takes place on the HTTP Working Group mailing list (<eref target="mailto:ietf-http-wg@w3.org"/>), which is archived at <eref target="https://lists.w3.org/Archives/Public/ietf-http-wg/"/>. Working Group information can be found at <eref target="https://httpwg.org/"/>.</t>
         <t>Source for this draft and an issue tracker can be found at <eref target="https://github.com/httpwg/http-extensions/labels/no-vary-search"/>.</t>
      </note>
   </front>
   <middle xmlns:xi="http://www.w3.org/2001/XInclude"><?line 112?>
      <section anchor="introduction">
         <name>Introduction</name>
         <t>HTTP caching <xref target="HTTP-CACHING"/> is based on reusing resources which match across a number of cache keys, with the most important one being the presented target URI (<xref section="7.1"
                  sectionFormat="of"
                  target="HTTP"
                  x:title="Determining the Target Resource"><?aug-anchor target.resource?></xref>). However, sometimes multiple URIs can represent the same resource. This leads to caches not always being as helpful as they could be: if the cache contains a response under one URI, but the response is then requested under another, the cached version will be ignored.</t>
         <t>The "No-Vary-Search" response header field defines a caching extension, as described in <xref section="4"
                  sectionFormat="of"
                  target="HTTP-CACHING"
                  x:title="Constructing Responses from Caches"><?aug-anchor constructing.responses.from.caches?></xref>, that tackles a specific subset of this general problem, for when different URIs that differ only in their query component identify the same resource. It allows resources to declare that some or all parts of the query component do not semantically affect the served response, and thus can be ignored for cache matching purposes. This is achieved by interpreting the query component as a sequence of parameters encoded using the <tt>application/x-www-form-urlencoded</tt> format <xref target="WHATWG-URL"/>. For example, if the order of the parameters within the query component does not affect which resource is identified, this is indicated using</t>
         <sourcecode type="http-message">
No-Vary-Search: key-order
</sourcecode>
         <t>If specific query parameters (e.g., ones indicating something for analytics) do not semantically affect the served resource, this is indicated using</t>
         <sourcecode type="http-message">
No-Vary-Search: params=("utm_source" "utm_medium" "utm_campaign")
</sourcecode>
         <t>And if the resource instead wants to take an allowlist-based approach, where only certain known query parameters semantically affect the served response, they can use</t>
         <sourcecode type="http-message">
No-Vary-Search: except=("productId")
</sourcecode>
         <t>Note that "cache busting", the practice of changing a part of the query component to create a distinct cache key and force retrieval of a newer response, can be made ineffective by the <tt>"No-Vary-Search"</tt> response header field.</t>
         <t>
            <xref target="header-definition"/> defines the new <tt>"No-Vary-Search"</tt> response header field, using the <xref target="STRUCTURED-FIELDS"/> framework. <xref target="data-model"/> and <xref target="parsing"/> illustrate the data model for how the field value can be represented in specifications, and the process for parsing the raw output from the structured field parser into that data model. <xref target="comparing"/> gives the key algorithm for comparing if two URLs are equivalent under the influence of the header field; notably, it leans on the decomposition of the query component into keys and values given by the <eref target="https://url.spec.whatwg.org/#concept-urlencoded">application/x-www-form-urlencoded</eref> format specified in <xref target="WHATWG-URL"/>. (As such, this header field is not useful for URLs whose query component does not follow that format.) Finally, <xref target="caching"/> explains how to extend <xref section="4"
                  sectionFormat="of"
                  target="HTTP-CACHING"
                  x:title="Constructing Responses from Caches"><?aug-anchor constructing.responses.from.caches?></xref> to take this new equivalence into account.</t>
         <t>From a deployment perspective, this extension is implemented by HTTP caches, including browser caches, content delivery networks, and forward proxies. Origin servers send the <tt>"No-Vary-Search"</tt> response header field to provide instructions to these caches. Caches that implement this extension use these instructions to determine when a previously stored response can be safely reused for a new request, even if the query components of the target URIs differ.</t>
      </section>
      <section anchor="conventions-and-definitions">
         <name>Conventions and Definitions</name>
         <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>", "<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as described in BCP 14 <xref target="RFC2119"/>
            <xref target="RFC8174"/> when, and only when, they appear in all capitals, as shown here.</t>
         <?line -18?>
         <t>In this document, the terms "URI" and "URL" are used interchangeably, depending on context. "URI" is used in the context of <xref target="URI"/>, <xref target="HTTP"/>, and <xref target="HTTP-CACHING"/>, whereas "URL" is used in the context of the algorithms specified in <xref target="WHATWG-URL"/>.</t>
         <t>The term "query parameters" in this document refers to the keys and values resulting from parsing a URL's query component using the <eref target="https://url.spec.whatwg.org/#concept-urlencoded">application/x-www-form-urlencoded</eref> format <xref target="WHATWG-URL"/>.</t>
         <t>This document also adopts some conventions and notation typical in WHATWG and W3C usage, especially as it relates to algorithms. See <xref target="WHATWG-INFRA"/>, and in particular:</t>
         <ul spacing="normal">
            <li>
               <t>its definition of lists, including the list literal notation « 1, 2, 3 ».</t>
            </li>
            <li>
               <t>its definition of strings, including their representation as code units.</t>
            </li>
         </ul>
         <t>(Other concepts used are called out using inline references.)</t>
      </section>
      <section anchor="header-definition">
         <name>HTTP header field definition</name>
         <t>The <tt>"No-Vary-Search"</tt> response header field is a structured field <xref target="STRUCTURED-FIELDS"/> whose value <bcp14>MUST</bcp14> be a dictionary (<xref section="3.2"
                  sectionFormat="of"
                  target="STRUCTURED-FIELDS"
                  x:title="Dictionaries"><?aug-anchor dictionary?></xref>).</t>
         <t>It has the following constraints:</t>
         <ul spacing="normal">
            <li>
               <t>If present, the <tt>key-order</tt> entry's value <bcp14>MUST</bcp14> be a boolean (<xref section="3.3.6"
                        sectionFormat="of"
                        target="STRUCTURED-FIELDS"
                        x:title="Booleans"><?aug-anchor boolean?></xref>).</t>
            </li>
            <li>
               <t>If present, the <tt>params</tt> entry's value <bcp14>MUST</bcp14> be an inner list of strings (<xref section="3.1.1"
                        sectionFormat="of"
                        target="STRUCTURED-FIELDS"
                        x:title="Inner Lists"><?aug-anchor inner-list?></xref>).</t>
            </li>
            <li>
               <t>If present, the <tt>except</tt> entry's value <bcp14>MUST</bcp14> be an inner list of strings (<xref section="3.1.1"
                        sectionFormat="of"
                        target="STRUCTURED-FIELDS"
                        x:title="Inner Lists"><?aug-anchor inner-list?></xref>).</t>
            </li>
            <li>
               <t>The <tt>except</tt> entry <bcp14>MUST NOT</bcp14> be present if the <tt>params</tt> entry is also present.</t>
            </li>
         </ul>
         <t>The dictionary <bcp14>MAY</bcp14> contain entries whose keys are not one of <tt>key-order</tt>, <tt>params</tt>, and <tt>except</tt>, but their meaning is not defined by this specification. Implementations of this specification will ignore such entries (but future documents might assign meaning to such entries). Future extensions to this dictionary <bcp14>MUST NOT</bcp14> restrict the set of URIs that are considered equivalent; they can only expand it. If a future extension requires restricting equivalence, it <bcp14>MUST</bcp14> be deployed as a new HTTP header field to ensure safety.</t>
         <t>The <tt>"No-Vary-Search"</tt> response header field is set by origin servers. Intermediaries <bcp14>MUST NOT</bcp14> insert, delete, or modify the field's value unless they are acting as the origin server for that response.</t>
         <aside>
            <t>A parsing algorithm is defined in <xref target="obtain-a-url-variation-config"/>.</t>
         </aside>
      </section>
      <section anchor="data-model">
         <name>Data model</name>
         <t>A <em>URL variation config</em> consists of the following:</t>
         <dl newline="true">
            <dt>no-vary params</dt>
            <dd>
               <t>either the special value <strong>wildcard</strong> or a list of strings</t>
            </dd>
            <dt>vary params</dt>
            <dd>
               <t>either the special value <strong>wildcard</strong> or a list of strings</t>
            </dd>
            <dt>vary on key order</dt>
            <dd>
               <t>a boolean</t>
            </dd>
         </dl>
         <t>
            <iref item="default URL variation config" primary="true"/> The <em>
               <iref item="default URL variation config"/>default URL variation config</em> is a URL variation config whose no-vary params is an empty list, vary params is <strong>wildcard</strong>, and vary on key order is true.</t>
         <t>The <iref item="obtain a URL variation config"/>
            <xref format="none" target="obtain-a-url-variation-config">obtain a URL variation config</xref> algorithm (<xref target="obtain-a-url-variation-config"/>) ensures that all URL variation configs obey the following constraints:</t>
         <ul spacing="normal">
            <li>
               <t>vary params is a list if and only if the no-vary params is <strong>wildcard</strong>; and</t>
            </li>
            <li>
               <t>no-vary params is a list if and only if the vary params is <strong>wildcard</strong>.</t>
            </li>
         </ul>
      </section>
      <section anchor="parsing">
         <name>Parsing</name>
         <section anchor="parse-a-url-variation-config">
            <name>Parse a URL variation config</name>
            <t>
               <iref item="parse a URL variation config" primary="true"/> To <em>
                  <iref item="parse a URL variation config"/>
                  <xref format="none" target="parse-a-url-variation-config">parse a URL variation config</xref>
               </em> given <em>value</em>:</t>
            <ol spacing="normal" type="1">
               <li>
                  <t>If <em>value</em> is null, then return the <iref item="default URL variation config"/>default URL variation config.</t>
               </li>
               <li>
                  <t>Let <em>result</em> be a new URL variation config.</t>
               </li>
               <li>
                  <t>Set <em>result</em>'s vary on key order to true.</t>
               </li>
               <li>
                  <t>If <em>value</em>["<tt>key-order</tt>"] exists:</t>
                  <ol spacing="normal" type="1">
                     <li>
                        <t>Let <em>keyOrderValue</em> be the <tt>item_or_inner_list</tt> component of the tuple <em>value</em>["<tt>key-order</tt>"] (ignoring any parameters).</t>
                     </li>
                     <li>
                        <t>If <em>keyOrderValue</em> is not a boolean, then return the <iref item="default URL variation config"/>default URL variation config.</t>
                     </li>
                     <li>
                        <t>Set <em>result</em>'s vary on key order to the boolean negation of <em>keyOrderValue</em>.</t>
                     </li>
                  </ol>
               </li>
               <li>
                  <t>If both <em>value</em>["<tt>params</tt>"] and <em>value</em>["<tt>except</tt>"] exist, then return the <iref item="default URL variation config"/>default URL variation config.</t>
               </li>
               <li>
                  <t>If neither <em>value</em>["<tt>params</tt>"] nor <em>value</em>["<tt>except</tt>"] exists:</t>
                  <ol spacing="normal" type="1">
                     <li>
                        <t>Set <em>result</em>'s no-vary params to an empty list.</t>
                     </li>
                     <li>
                        <t>Set <em>result</em>'s vary params to <strong>wildcard</strong>.</t>
                     </li>
                  </ol>
               </li>
               <li>
                  <t>If <em>value</em>["<tt>params</tt>"] exists:</t>
                  <ol spacing="normal" type="1">
                     <li>
                        <t>Let <em>paramsValue</em> be the <tt>item_or_inner_list</tt> component of the tuple <em>value</em>["<tt>params</tt>"] (ignoring any parameters).</t>
                     </li>
                     <li>
                        <t>If <em>paramsValue</em> is not an inner list, then return the <iref item="default URL variation config"/>default URL variation config.</t>
                     </li>
                     <li>
                        <t>Let <em>paramsList</em> be a list containing the <tt>bare_item</tt> component of each tuple in <em>paramsValue</em> (ignoring any parameters).</t>
                     </li>
                     <li>
                        <t>If any item in <em>paramsList</em> is not a string, then return the <iref item="default URL variation config"/>default URL variation config.</t>
                     </li>
                     <li>
                        <t>Set <em>result</em>'s no-vary params to the result of applying <iref item="parse a key"/>
                           <xref format="none" target="parse-a-key">parse a key</xref> (<xref target="parse-a-key"/>) to each item in <em>paramsList</em>.</t>
                     </li>
                     <li>
                        <t>Set <em>result</em>'s vary params to <strong>wildcard</strong>.</t>
                     </li>
                  </ol>
               </li>
               <li>
                  <t>Otherwise, if <em>value</em>["<tt>except</tt>"] exists:</t>
                  <ol spacing="normal" type="1">
                     <li>
                        <t>Let <em>exceptValue</em> be the <tt>item_or_inner_list</tt> component of the tuple <em>value</em>["<tt>except</tt>"] (ignoring any parameters).</t>
                     </li>
                     <li>
                        <t>If <em>exceptValue</em> is not an inner list, then return the <iref item="default URL variation config"/>default URL variation config.</t>
                     </li>
                     <li>
                        <t>Let <em>exceptList</em> be a list containing the <tt>bare_item</tt> component of each tuple in <em>exceptValue</em> (ignoring any parameters).</t>
                     </li>
                     <li>
                        <t>If any item in <em>exceptList</em> is not a string, then return the <iref item="default URL variation config"/>default URL variation config.</t>
                     </li>
                     <li>
                        <t>Set <em>result</em>'s vary params to the result of applying <iref item="parse a key"/>
                           <xref format="none" target="parse-a-key">parse a key</xref> (<xref target="parse-a-key"/>) to each item in <em>exceptList</em>.</t>
                     </li>
                     <li>
                        <t>Set <em>result</em>'s no-vary params to <strong>wildcard</strong>.</t>
                     </li>
                  </ol>
               </li>
               <li>
                  <t>Return <em>result</em>.</t>
               </li>
            </ol>
            <aside>
               <t>In general, this algorithm is strict and tends to return the <iref item="default URL variation config"/>default URL variation config whenever it sees something it doesn't recognize. This is because the <iref item="default URL variation config"/>default URL variation config behavior will just cause fewer cache hits, which is an acceptable fallback behavior.</t>
            </aside>
            <aside>
               <t>The input to this algorithm is generally obtained by parsing a structured field (<xref section="4.2"
                        sectionFormat="of"
                        target="STRUCTURED-FIELDS"
                        x:title="Parsing Structured Fields"><?aug-anchor text-parse?></xref>) using field_type "dictionary".</t>
            </aside>
         </section>
         <section anchor="obtain-a-url-variation-config">
            <name>Obtain a URL variation config</name>
            <t>
               <iref item="obtain a URL variation config" primary="true"/> To <em>
                  <iref item="obtain a URL variation config"/>
                  <xref format="none" target="obtain-a-url-variation-config">obtain a URL variation config</xref>
               </em> given an HTTP response (<xref section="3.4"
                     sectionFormat="of"
                     target="HTTP"
                     x:title="Messages"><?aug-anchor messages?></xref>) <em>response</em>:</t>
            <ol spacing="normal" type="1">
               <li>
                  <t>Let <em>fieldValue</em> be the result of parsing the <tt>"No-Vary-Search"</tt> response header field from <em>response</em> as a Dictionary (<xref section="4.2"
                           sectionFormat="of"
                           target="STRUCTURED-FIELDS"
                           x:title="Parsing Structured Fields"><?aug-anchor text-parse?></xref>). If parsing fails or the field is absent, let <em>fieldValue</em> be null.</t>
               </li>
               <li>
                  <t>Return the result of parsing a URL variation config (<xref target="parse-a-url-variation-config"/>) given <em>fieldValue</em>. <iref item="parse a URL variation config"/>
                  </t>
               </li>
            </ol>
            <section anchor="examples">
               <name>Examples</name>
               <t>The following illustrates how various inputs are parsed, in terms of their impact on the resulting no-vary params and vary params:</t>
               <table>
                  <thead>
                     <tr>
                        <th align="left">Input</th>
                        <th align="left">Result</th>
                     </tr>
                  </thead>
                  <tbody>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: key-order</tt>
                        </td>
                        <td align="left">no-vary params: (empty list)<br/>vary params: <strong>wildcard</strong>
                           <br/>vary on key order: false</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=("a")</tt>
                        </td>
                        <td align="left">no-vary params: « "<tt>a</tt>" »<br/>vary params: <strong>wildcard</strong>
                        </td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: except=("x")</tt>
                        </td>
                        <td align="left">no-vary params: <strong>wildcard</strong>
                           <br/>vary params: « "<tt>x</tt>" »</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=()</tt>
                        </td>
                        <td align="left">no-vary params: (empty list)<br/>vary params: <strong>wildcard</strong>
                        </td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: except=()</tt>
                        </td>
                        <td align="left">no-vary params: <strong>wildcard</strong>
                           <br/>vary params: (empty list)</td>
                     </tr>
                  </tbody>
               </table>
               <t>The following inputs are all invalid and will cause the <iref item="default URL variation config"/>default URL variation config to be returned:</t>
               <table>
                  <thead>
                     <tr>
                        <th align="left">Input</th>
                        <th align="left">Explanation</th>
                     </tr>
                  </thead>
                  <tbody>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: key-order="not a boolean"</tt>
                        </td>
                        <td align="left">
                           <tt>key-order</tt> expects a boolean, not a string</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params="not an inner list"</tt>
                        </td>
                        <td align="left">
                           <tt>params</tt> expects an inner list, not a string</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=(not-a-string)</tt>
                        </td>
                        <td align="left">
                           <tt>params</tt> items must be strings (tokens are invalid)</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=?0</tt>
                        </td>
                        <td align="left">
                           <tt>params</tt> expects an inner list, not a boolean</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=?1</tt>
                        </td>
                        <td align="left">
                           <tt>params</tt> expects an inner list, not a boolean</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=?1, except=("x")</tt>
                        </td>
                        <td align="left">
                           <tt>params</tt> and <tt>except</tt> cannot both be present</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=("a"), except=("x")</tt>
                        </td>
                        <td align="left">
                           <tt>params</tt> and <tt>except</tt> cannot both be present</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=(), except=()</tt>
                        </td>
                        <td align="left">
                           <tt>params</tt> and <tt>except</tt> cannot both be present</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: except="not an inner list"</tt>
                        </td>
                        <td align="left">
                           <tt>except</tt> expects an inner list, not a string</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: except=(not-a-string)</tt>
                        </td>
                        <td align="left">
                           <tt>except</tt> items must be strings (tokens are invalid)</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: except=?1</tt>
                        </td>
                        <td align="left">
                           <tt>except</tt> expects an inner list, not a boolean</td>
                     </tr>
                  </tbody>
               </table>
               <t>The following inputs are valid, but somewhat unconventional. They are shown alongside their more conventional form.</t>
               <table>
                  <thead>
                     <tr>
                        <th align="left">Input</th>
                        <th align="left">Conventional form</th>
                     </tr>
                  </thead>
                  <tbody>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: key-order=?1</tt>
                        </td>
                        <td align="left">
                           <tt>No-Vary-Search: key-order</tt>
                        </td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: except=("x")</tt>, key-order</td>
                        <td align="left">
                           <tt>No-Vary-Search: key-order, except=("x")</tt>
                        </td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: params=()</tt>
                        </td>
                        <td align="left">(omit the header field)</td>
                     </tr>
                     <tr>
                        <td align="left">
                           <tt>No-Vary-Search: key-order=?0</tt>
                        </td>
                        <td align="left">(omit the header field)</td>
                     </tr>
                  </tbody>
               </table>
            </section>
         </section>
         <section anchor="parse-a-key">
            <name>Parse a key</name>
            <t>
               <iref item="parse a key" primary="true"/> To <em>
                  <iref item="parse a key"/>
                  <xref format="none" target="parse-a-key">parse a key</xref>
               </em> given an ASCII string <em>keyString</em>:</t>
            <ol spacing="normal" type="1">
               <li>
                  <t>Let <em>keyBytes</em> be the <eref target="https://infra.spec.whatwg.org/#isomorphic-encode">isomorphic encoding</eref>
                     <xref target="WHATWG-INFRA"/> of <em>keyString</em>.</t>
               </li>
               <li>
                  <t>Replace any 0x2B (+) in <em>keyBytes</em> with 0x20 (SP).</t>
               </li>
               <li>
                  <t>Let <em>keyBytesDecoded</em> be the <eref target="https://url.spec.whatwg.org/#percent-decode">percent-decoding</eref>
                     <xref target="WHATWG-URL"/> of <em>keyBytes</em>.</t>
               </li>
               <li>
                  <t>Let <em>keyStringDecoded</em> be the <eref target="https://encoding.spec.whatwg.org/#utf-8-decode-without-bom">UTF-8 decoding without BOM</eref>
                     <xref target="WHATWG-ENCODING"/> of <em>keyBytesDecoded</em>.</t>
               </li>
               <li>
                  <t>Return <em>keyStringDecoded</em>.</t>
               </li>
            </ol>
            <section anchor="examples-1">
               <name>Examples</name>
               <t>The <iref item="parse a key"/>
                  <xref format="none" target="parse-a-key">parse a key</xref> algorithm allows encoding non-ASCII key strings in the ASCII structured header field format, similar to how the <eref target="https://url.spec.whatwg.org/#concept-urlencoded">application/x-www-form-urlencoded</eref> format <xref target="WHATWG-URL"/> allows encoding an entire entry list of keys and values in a URI (which is restricted to ASCII characters). For example:</t>
               <sourcecode type="http-message">
No-Vary-Search: params=("%C3%A9+%E6%B0%97")
</sourcecode>
               <t>Notice that while the input string <tt>"%C3%A9+%E6%B0%97"</tt> consists entirely of ASCII characters (as required at the HTTP layer), the percent-decoding step used by the cache produces a non-ASCII result. This will result in a URL variation config whose no-vary params are « "<tt>é 気</tt>" ». Note that the "<tt>+</tt>" character in the encoded string is mapped to a space (SP). As explained in a later example, the canonicalization process during equivalence testing means this will treat as equivalent URIs such as:</t>
               <!-- link "a later example" and "equivalence testing" -->
               <ul spacing="normal">
                  <li>
                     <t>
                        <tt>https://example.com/?é 気=1</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>https://example.com/?é+気=2</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>https://example.com/?%C3%A9%20気=3</tt>
                     </t>
                  </li>
                  <li>
                     <t>
                        <tt>https://example.com/?%C3%A9+%E6%B0%97=4</tt>
                     </t>
                  </li>
               </ul>
               <t>and so on, since they all are <eref target="https://url.spec.whatwg.org/#concept-urlencoded-parser">parsed</eref>
                  <xref target="WHATWG-URL"/> to having the same key "<tt>é 気</tt>".</t>
            </section>
         </section>
      </section>
      <section anchor="comparing">
         <name>Comparing</name>
         <t>
            <iref item="equivalent modulo variation config" primary="true"/> Two <eref target="https://url.spec.whatwg.org/#concept-url">URLs</eref>
            <xref target="WHATWG-URL"/>
            <em>urlA</em> and <em>urlB</em> are <em>equivalent modulo variation config</em> given a URL variation config <em>variationConfig</em> if the following algorithm returns true:</t>
         <ol spacing="normal" type="1">
            <li>
               <t>If the scheme, host, port, or path of <em>urlA</em> and <em>urlB</em> differ, then return false.</t>
            </li>
            <li>
               <t>If <em>variationConfig</em> is equivalent to the <iref item="default URL variation config"/>default URL variation config, then:</t>
               <ol spacing="normal" type="1">
                  <li>
                     <t>If <em>urlA</em>'s query equals <em>urlB</em>'s query, then return true.</t>
                  </li>
                  <li>
                     <t>Return false.</t>
                  </li>
               </ol>
               <t>In this case, even URL pairs that might appear the same after running the <eref target="https://url.spec.whatwg.org/#concept-urlencoded-parser">application/x-www-form-urlencoded parser</eref>
                  <xref target="WHATWG-URL"/> on their queries, such as <tt>https://example.com/a</tt> and <tt>https://example.com/a?</tt>, or <tt>https://example.com/foo?a=b&amp;&amp;&amp;c</tt> and <tt>https://example.com/foo?a=b&amp;c=</tt>, will be treated as inequivalent.</t>
            </li>
            <li>
               <t>Let <em>searchParamsA</em> and <em>searchParamsB</em> be empty lists.</t>
            </li>
            <li>
               <t>If <em>urlA</em>'s query is not null, then set <em>searchParamsA</em> to the result of running the <eref target="https://url.spec.whatwg.org/#concept-urlencoded-parser">application/x-www-form-urlencoded parser</eref>
                  <xref target="WHATWG-URL"/> given the <eref target="https://infra.spec.whatwg.org/#isomorphic-encode">isomorphic encoding</eref>
                  <xref target="WHATWG-INFRA"/> of <em>urlA</em>'s query.</t>
            </li>
            <li>
               <t>If <em>urlB</em>'s query is not null, then set <em>searchParamsB</em> to the result of running the <eref target="https://url.spec.whatwg.org/#concept-urlencoded-parser">application/x-www-form-urlencoded parser</eref>
                  <xref target="WHATWG-URL"/> given the <eref target="https://infra.spec.whatwg.org/#isomorphic-encode">isomorphic encoding</eref>
                  <xref target="WHATWG-INFRA"/> of <em>urlB</em>'s query.</t>
            </li>
            <li>
               <t>If <em>variationConfig</em>'s no-vary params is a list, then:</t>
               <ol spacing="normal" type="1">
                  <li>
                     <t>Set <em>searchParamsA</em> to a list containing those items <em>pair</em> in <em>searchParamsA</em> where <em>variationConfig</em>'s no-vary params does not contain <em>pair</em>[0].</t>
                  </li>
                  <li>
                     <t>Set <em>searchParamsB</em> to a list containing those items <em>pair</em> in <em>searchParamsB</em> where <em>variationConfig</em>'s no-vary params does not contain <em>pair</em>[0].</t>
                  </li>
               </ol>
            </li>
            <li>
               <t>Otherwise, if <em>variationConfig</em>'s vary params is a list, then:</t>
               <ol spacing="normal" type="1">
                  <li>
                     <t>Set <em>searchParamsA</em> to a list containing those items <em>pair</em> in <em>searchParamsA</em> where <em>variationConfig</em>'s vary params contains <em>pair</em>[0].</t>
                  </li>
                  <li>
                     <t>Set <em>searchParamsB</em> to a list containing those items <em>pair</em> in <em>searchParamsB</em> where <em>variationConfig</em>'s vary params contains <em>pair</em>[0].</t>
                  </li>
               </ol>
            </li>
            <li>
               <t>If <em>variationConfig</em>'s vary on key order is false, then:</t>
               <ol spacing="normal" type="1">
                  <li>
                     <t>Let <em>keyLessThan</em> be an algorithm taking as inputs two pairs (<em>keyA</em>, <em>valueA</em>) and (<em>keyB</em>, <em>valueB</em>), which returns whether <em>keyA</em> is <eref target="https://infra.spec.whatwg.org/#code-unit-less-than">code unit less than</eref>
                        <xref target="WHATWG-INFRA"/>
                        <em>keyB</em>.</t>
                  </li>
                  <li>
                     <t>Set <em>searchParamsA</em> to the result of <eref target="https://infra.spec.whatwg.org/#list-sort-in-ascending-order">sorting</eref>
                        <xref target="WHATWG-INFRA"/>
                        <em>searchParamsA</em> in ascending order with <em>keyLessThan</em>.</t>
                  </li>
                  <li>
                     <t>Set <em>searchParamsB</em> to the result of <eref target="https://infra.spec.whatwg.org/#list-sort-in-ascending-order">sorting</eref>
                        <xref target="WHATWG-INFRA"/>
                        <em>searchParamsB</em> in ascending order with <em>keyLessThan</em>.</t>
                  </li>
               </ol>
            </li>
            <li>
               <t>If <em>searchParamsA</em>'s size is not equal to <em>searchParamsB</em>'s size, then return false.</t>
            </li>
            <li>
               <t>Let <em>i</em> be 0.</t>
            </li>
            <li>
               <t>While <em>i</em> &lt; <em>searchParamsA</em>'s size:</t>
               <ol spacing="normal" type="1">
                  <li>
                     <t>If <em>searchParamsA</em>[<em>i</em>][0] does not equal <em>searchParamsB</em>[<em>i</em>][0], then return false.</t>
                  </li>
                  <li>
                     <t>If <em>searchParamsA</em>[<em>i</em>][1] does not equal <em>searchParamsB</em>[<em>i</em>][1], then return false.</t>
                  </li>
                  <li>
                     <t>Set <em>i</em> to <em>i</em> + 1.</t>
                  </li>
               </ol>
            </li>
            <li>
               <t>Return true.</t>
            </li>
         </ol>
         <section anchor="examples-2">
            <name>Examples</name>
            <t>Due to how the application/x-www-form-urlencoded parser canonicalizes query strings, there are some cases where query strings which do not appear obviously equivalent, will end up being treated as equivalent after parsing.</t>
            <t>So, for example, given any non-default value for the <tt>"No-Vary-Search"</tt> response header field, such as <tt>No-Vary-Search: key-order</tt>, we will have the following equivalences:</t>
            <table>
               <thead>
                  <tr>
                     <th align="left">First Query</th>
                     <th align="left">Second Query</th>
                     <th align="left">Explanation</th>
                  </tr>
               </thead>
               <tbody>
                  <tr>
                     <td align="left">null</td>
                     <td align="left">
                        <tt>?</tt>
                     </td>
                     <td align="left">A null query is parsed the same as an empty string</td>
                  </tr>
                  <tr>
                     <td align="left">
                        <tt>?a=x</tt>
                     </td>
                     <td align="left">
                        <tt>?%61=%78</tt>
                     </td>
                     <td align="left">Parsing performs percent-decoding</td>
                  </tr>
                  <tr>
                     <td align="left">
                        <tt>?a=é</tt>
                     </td>
                     <td align="left">
                        <tt>?a=%C3%A9</tt>
                     </td>
                     <td align="left">Parsing performs percent-decoding</td>
                  </tr>
                  <tr>
                     <td align="left">
                        <tt>?a=%f6</tt>
                     </td>
                     <td align="left">
                        <tt>?a=%ef%bf%bd</tt>
                     </td>
                     <td align="left">An invalid UTF-8 sequence and the literal U+FFFD character are both parsed as U+FFFD ( )</td>
                  </tr>
                  <tr>
                     <td align="left">
                        <tt>?a=x&amp;&amp;&amp;&amp;</tt>
                     </td>
                     <td align="left">
                        <tt>?a=x</tt>
                     </td>
                     <td align="left">Parsing splits on <tt>&amp;</tt> and discards empty strings</td>
                  </tr>
                  <tr>
                     <td align="left">
                        <tt>?a=</tt>
                     </td>
                     <td align="left">
                        <tt>?a</tt>
                     </td>
                     <td align="left">Both parse as having an empty string value for <tt>a</tt>
                     </td>
                  </tr>
                  <tr>
                     <td align="left">
                        <tt>?a=%20</tt>
                     </td>
                     <td align="left">
                        <tt>?a= &amp;</tt>
                     </td>
                     <td align="left">
                        <tt>%20</tt> is parsed as U+0020 SPACE</td>
                  </tr>
                  <tr>
                     <td align="left">
                        <tt>?a=+</tt>
                     </td>
                     <td align="left">
                        <tt>?a= &amp;</tt>
                     </td>
                     <td align="left">
                        <tt>+</tt> is parsed as U+0020 SPACE</td>
                  </tr>
               </tbody>
            </table>
            <t>Note that no Unicode normalization is performed during this comparison. For example, a query string of <tt>?a=%C3%A9</tt> (using the NFC encoding of <tt>é</tt>) and <tt>?a=e%CC%81</tt> (using the NFD encoding of <tt>é</tt>) will not be treated as equivalent.</t>
         </section>
      </section>
      <section anchor="caching">
         <name>Caching</name>
         <t>To reuse a stored response, <xref section="4"
                  sectionFormat="of"
                  target="HTTP-CACHING"
                  x:title="Constructing Responses from Caches"><?aug-anchor constructing.responses.from.caches?></xref> requires that the presented target URI and that of the stored response match. If a cache implements the <tt>No-Vary-Search</tt> extension, this matching requirement is also satisfied if the URIs are equivalent modulo URL variation config (<xref target="comparing"/>) given the stored response's <tt>No-Vary-Search</tt> header.</t>
         <t>This document does not alter the requirements for cache invalidation (see <xref target="HTTP-CACHING"
                  x:fmt="of"
                  x:sec="4.4"
                  x:title="Invalidating Stored Responses"><?aug-anchor invalidation?></xref>). A cache <bcp14>MAY</bcp14> invalidate stored responses for URIs that are equivalent modulo URL variation config, but is not required to do so. Therefore, state-changing requests might not invalidate all conceptually equivalent responses.</t>
         <t>Note that the <tt>"No-Vary-Search"</tt> response header field operates in addition to content negotiation and the <tt>Vary</tt> header field (see <xref target="HTTP-CACHING"
                  x:fmt="of"
                  x:sec="4.1"
                  x:title="Calculating Cache Keys with the Vary Header Field"><?aug-anchor caching.negotiated.responses?></xref>).</t>
         <t>Cache implementations <bcp14>MAY</bcp14> fail to reuse a stored response whose target URI matches <em>only</em> modulo URL variation config, if the cache has a stored response with a more recent <tt>Date</tt> header field which:</t>
         <ul spacing="normal">
            <li>
               <t>has a target URI which is equal to the presented target URI, excluding the query, and</t>
            </li>
            <li>
               <t>has a non-empty value for the <tt>"No-Vary-Search"</tt> response header field, and</t>
            </li>
            <li>
               <t>has a <tt>"No-Vary-Search"</tt> response header field value different from the stored response being considered for reuse.</t>
            </li>
         </ul>
         <t>When a cache has multiple stored responses with conflicting <tt>"No-Vary-Search"</tt> values, preferring the response with the most recent <tt>Date</tt> header field helps ensure caches converge on the origin's latest caching policy.</t>
         <aside>
            <t>Caches aren't required to reuse stored responses, generally. However, the above expressly empowers caches to, if it is advantageous for performance or other reasons, search a smaller number of stored responses.</t>
            <t>That is, because caches might store more than one response for a given target URI path and authority, they need a way to efficiently look up the <tt>"No-Vary-Search"</tt> response header field value without accessing all cached responses. Such a cache might take steps like the following to identify a stored response in a performant way, before checking the other conditions in <xref section="4"
                     sectionFormat="of"
                     target="HTTP-CACHING"
                     x:title="Constructing Responses from Caches"><?aug-anchor constructing.responses.from.caches?></xref>:</t>
            <ol spacing="normal" type="1">
               <li>
                  <t>Let exactMatch be cache[presentedTargetURI]. If it is a stored response that can be reused, return it.</t>
               </li>
               <li>
                  <t>Let targetPath be presentedTargetURI, with query parameters removed.</t>
               </li>
               <li>
                  <t>Let lastNVS be mostRecentNVS[targetPath]. If it does not exist, return null.</t>
               </li>
               <li>
                  <t>Let simplifiedURL be the result of simplifying presentedTargetURI according to lastNVS (by removing query parameters which are not significant, and <eref target="https://infra.spec.whatwg.org/#list-sort-in-ascending-order">sorting</eref>
                     <xref target="WHATWG-INFRA"/> parameters in ascending order by key, if key order is to be ignored).</t>
               </li>
               <li>
                  <t>Let nvsMatch be cache[simplifiedURL]. If it does not exist, return null. (It is assumed that this was written when storing in the cache, in addition to the exact URL.)</t>
               </li>
               <li>
                  <t>Let variationConfig be obtained (<xref target="obtain-a-url-variation-config"/>) from nvsMatch.</t>
               </li>
               <li>
                  <t>If nvsMatch's target URI and presentedTargetURI are not equivalent modulo URL variation config (<xref target="comparing"/>) given variationConfig, then return null.</t>
               </li>
               <li>
                  <t>If nvsMatch is a stored response that can be reused, return it. Otherwise, return null.</t>
               </li>
            </ol>
         </aside>
         <t>To aid cache implementation efficiency, servers <bcp14>SHOULD NOT</bcp14> send different non-empty values for the <tt>"No-Vary-Search"</tt> response header field in response to requests for a given target URI path and authority over time, unless there is a need to update how they handle the query component. Doing so would cause cache implementations that use a strategy like the above to miss some stored responses that could otherwise have been reused.</t>
      </section>
      <section anchor="security-considerations">
         <name>Security Considerations</name>
         <t>The main risk to be aware of is a cache returning a response that was originally fetched from a URL different from the one requested. In a web browser, this could cause the user to see a response fetched from a URL different from the one displayed when they hovered a link, or the URL displayed in the URL bar.</t>
         <t>For shared caches, such as CDNs or forward proxies, returning a response for a different URL carries the risk of cross-user state leakage. If a server incorrectly declares that a query parameter does not affect the response, but that parameter actually dictates user-specific or sensitive content, the shared cache might serve one user's personalized response to another user. However, because the origin strictly controls the <tt>"No-Vary-Search"</tt> response header field, it is the origin's responsibility to ensure that ignored parameters are safe to disregard for all users.</t>
         <t>The <tt>"No-Vary-Search"</tt> response header field alters the algorithm that caches use for URI identifier comparison. As discussed in <xref target="RFC6943"/>, altering identifier comparison logic can lead to security issues, primarily through "false positives" where two identifiers are incorrectly deemed equivalent.</t>
         <t>Because URL query parsing replaces invalid percent-encoded UTF-8 sequences with <tt>U+FFFD</tt>, lossy decoding can map distinct query strings onto the same cache key (for example, <tt>?a=%f6</tt> and <tt>?a=%ef%bf%bd</tt>). Origins should not rely on invalid percent-encoded sequences being distinguishable, as this is a concrete example of the false positives warned about in <xref target="RFC6943"/>.</t>
         <t>Incorrect configuration of this field can exacerbate cache poisoning or data leakage risks by causing such false positives. Origin servers <bcp14>MUST NOT</bcp14> declare a parameter as no-vary if doing so would bypass server processing required for safe response reuse. This includes parameters used for authorization, user identification, signature verification, user consent, routing, auditing, revocation, or any other security-sensitive operations.</t>
         <t>However, since the impact is limited to query parameters, this does not cross the relevant security boundary, which is the origin (<xref target="ORIGIN"/>). (See also the <eref target="https://url.spec.whatwg.org/#concept-url-host">host</eref> from <eref target="https://url.spec.whatwg.org/#url-rendering-simplification">the perspective of web browser security UI</eref>
            <xref target="WHATWG-URL"/>). Indeed, origins already have complete control over how they present URLs and response bodies, including on the client side via technology such as <eref target="https://html.spec.whatwg.org/multipage/nav-history-apis.html#dom-history-replacestate">history.replaceState()</eref>
            <xref target="HTML"/> or service workers.</t>
      </section>
      <section anchor="privacy-considerations">
         <name>Privacy Considerations</name>
         <t>This proposal is adjacent to the highly-privacy-relevant space of <eref target="https://privacycg.github.io/nav-tracking-mitigations/#terminology">navigational tracking</eref>, which often uses query parameters to pass along user identifiers. If an origin were to encode user identifiers in its URI, this proposal can reduce user tracking by private caches, since preventing server processing of such user IDs bypasses the server in favor of the cache. It does not interfere with <eref target="https://privacycg.github.io/nav-tracking-mitigations/#deployed-mitigations">existing navigational tracking mitigations</eref>, or any known future ones being contemplated. <xref target="NAV-TRACKING-MITIGATIONS"/>
         </t>
         <t>However, this tracking reduction does not fully apply to shared caches (such as content delivery networks and forward proxies), which still receive the requests containing the identifiers. Furthermore, an errant configuration that incorrectly ignores parameters related to user identity or private state could expose cached content meant for one user to another. While this mistake can occur with standard caching, the <tt>"No-Vary-Search"</tt> response header field increases the surface area for such misconfigurations, making it critical that origins accurately classify their query parameters.</t>
      </section>
      <section anchor="iana-considerations">
         <name>IANA Considerations</name>
         <section anchor="http-field-names">
            <name>HTTP Field Names</name>
            <t>IANA is requested to enter the following into the Hypertext Transfer Protocol (HTTP) Field Name Registry (<eref target="https://www.iana.org/assignments/http-fields/http-fields.xhtml">https://www.iana.org/assignments/http-fields/http-fields.xhtml</eref>):</t>
            <dl>
               <dt>Field Name:</dt>
               <dd>
                  <t>
                     <tt>No-Vary-Search</tt>
                  </t>
               </dd>
               <dt>Status:</dt>
               <dd>
                  <t>permanent</t>
               </dd>
               <dt>Structured Type:</dt>
               <dd>
                  <t>Dictionary</t>
               </dd>
               <dt>Reference:</dt>
               <dd>
                  <t>this document</t>
               </dd>
               <dt>Comments:</dt>
               <dd>
                  <t>(none)</t>
               </dd>
            </dl>
         </section>
         <section anchor="no-vary-search-dictionary-keys-registry">
            <name>No-Vary-Search Dictionary Keys Registry</name>
            <t>IANA is requested to create a new registry, "No-Vary-Search Dictionary Keys", at <eref target="https://www.iana.org/assignments/http-fields/">https://www.iana.org/assignments/http-fields/</eref>.</t>
            <t>The registration policy is "IETF Review" (see <xref target="RFC8126" x:fmt="of" x:sec="4.8"/>).</t>
            <t>A registration request <bcp14>MUST</bcp14> include the following fields:</t>
            <ul spacing="normal">
               <li>
                  <t>Key: the dictionary key for the <tt>"No-Vary-Search"</tt> response header field</t>
               </li>
               <li>
                  <t>Description: a brief description of the key's purpose</t>
               </li>
               <li>
                  <t>Reference: a pointer to the specification that defines the key</t>
               </li>
            </ul>
            <t>The initial contents of this registry are:</t>
            <table>
               <thead>
                  <tr>
                     <th align="left">Key</th>
                     <th align="left">Description</th>
                     <th align="left">Reference</th>
                  </tr>
               </thead>
               <tbody>
                  <tr>
                     <td align="left">
                        <tt>key-order</tt>
                     </td>
                     <td align="left">Indicates if query parameter order affects caching</td>
                     <td align="left">this document</td>
                  </tr>
                  <tr>
                     <td align="left">
                        <tt>params</tt>
                     </td>
                     <td align="left">A list of query parameters that do not affect caching</td>
                     <td align="left">this document</td>
                  </tr>
                  <tr>
                     <td align="left">
                        <tt>except</tt>
                     </td>
                     <td align="left">A list of query parameters that affect caching</td>
                     <td align="left">this document</td>
                  </tr>
               </tbody>
            </table>
         </section>
      </section>
   </middle>
   <back xmlns:xi="http://www.w3.org/2001/XInclude">
      <references anchor="sec-combined-references">
         <name>References</name>
         <references anchor="sec-normative-references">
            <name>Normative References</name>
            <reference anchor="URI">
               <front>
                  <title>Uniform Resource Identifier (URI): Generic Syntax</title>
                  <author fullname="T. Berners-Lee" initials="T." surname="Berners-Lee"/>
                  <author fullname="R. Fielding" initials="R." surname="Fielding"/>
                  <author fullname="L. Masinter" initials="L." surname="Masinter"/>
                  <date month="January" year="2005"/>
               </front>
               <seriesInfo name="STD" value="66"/>
               <seriesInfo name="RFC" value="3986"/>
               <seriesInfo name="DOI" value="10.17487/RFC3986"/>
               <x:source basename="rfc3986" href="rfc3986.xml"/>
            </reference>
            <reference anchor="HTTP">
               <front>
                  <title>HTTP Semantics</title>
                  <author fullname="R. Fielding"
                          initials="R."
                          role="editor"
                          surname="Fielding"/>
                  <author fullname="M. Nottingham"
                          initials="M."
                          role="editor"
                          surname="Nottingham"/>
                  <author fullname="J. Reschke"
                          initials="J."
                          role="editor"
                          surname="Reschke"/>
                  <date month="June" year="2022"/>
               </front>
               <seriesInfo name="STD" value="97"/>
               <seriesInfo name="RFC" value="9110"/>
               <seriesInfo name="DOI" value="10.17487/RFC9110"/>
               <x:source basename="rfc9110" href="rfc9110.xml"/>
            </reference>
            <reference anchor="HTTP-CACHING">
               <front>
                  <title>HTTP Caching</title>
                  <author fullname="R. Fielding"
                          initials="R."
                          role="editor"
                          surname="Fielding"/>
                  <author fullname="M. Nottingham"
                          initials="M."
                          role="editor"
                          surname="Nottingham"/>
                  <author fullname="J. Reschke"
                          initials="J."
                          role="editor"
                          surname="Reschke"/>
                  <date month="June" year="2022"/>
               </front>
               <seriesInfo name="STD" value="98"/>
               <seriesInfo name="RFC" value="9111"/>
               <seriesInfo name="DOI" value="10.17487/RFC9111"/>
               <x:source basename="rfc9111" href="rfc9111.xml"/>
            </reference>
            <reference anchor="STRUCTURED-FIELDS">
               <front>
                  <title>Structured Field Values for HTTP</title>
                  <author fullname="M. Nottingham" initials="M." surname="Nottingham"/>
                  <author fullname="P-H. Kamp" surname="P-H. Kamp"/>
                  <date month="September" year="2024"/>
               </front>
               <seriesInfo name="RFC" value="9651"/>
               <seriesInfo name="DOI" value="10.17487/RFC9651"/>
               <x:source basename="rfc9651" href="rfc9651.xml"/>
            </reference>
            <reference anchor="WHATWG-ENCODING" target="https://encoding.spec.whatwg.org/">
               <front>
                  <title>Encoding Living Standard</title>
                  <author fullname="Anne van Kesteren" initials="A." surname="van Kesteren">
                     <organization>Apple Inc.</organization>
                  </author>
                  <date day="21" month="May" year="2026"/>
               </front>
               <annotation>WHATWG</annotation>
            </reference>
            <reference anchor="WHATWG-INFRA" target="https://infra.spec.whatwg.org/">
               <front>
                  <title>Infra Living Standard</title>
                  <author fullname="Anne van Kesteren" initials="A." surname="van Kesteren">
                     <organization>Apple Inc.</organization>
                  </author>
                  <author fullname="Domenic Denicola" initials="D." surname="Denicola">
                     <organization>Google LLC</organization>
                  </author>
                  <date day="17" month="July" year="2026"/>
               </front>
               <annotation>WHATWG</annotation>
            </reference>
            <reference anchor="WHATWG-URL" target="https://url.spec.whatwg.org/">
               <front>
                  <title>URL Living Standard</title>
                  <author fullname="Anne van Kesteren" initials="A." surname="van Kesteren">
                     <organization>Apple Inc.</organization>
                  </author>
                  <date day="06" month="July" year="2026"/>
               </front>
               <annotation>WHATWG</annotation>
            </reference>
            <reference anchor="RFC2119">
               <front>
                  <title>Key words for use in RFCs to Indicate Requirement Levels</title>
                  <author fullname="S. Bradner" initials="S." surname="Bradner"/>
                  <date month="March" year="1997"/>
               </front>
               <seriesInfo name="BCP" value="14"/>
               <seriesInfo name="RFC" value="2119"/>
               <seriesInfo name="DOI" value="10.17487/RFC2119"/>
            </reference>
            <reference anchor="RFC8174">
               <front>
                  <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
                  <author fullname="B. Leiba" initials="B." surname="Leiba"/>
                  <date month="May" year="2017"/>
               </front>
               <seriesInfo name="BCP" value="14"/>
               <seriesInfo name="RFC" value="8174"/>
               <seriesInfo name="DOI" value="10.17487/RFC8174"/>
            </reference>
         </references>
         <references anchor="sec-informative-references">
            <name>Informative References</name>
            <reference anchor="HTML" target="https://html.spec.whatwg.org/">
               <front>
                  <title>HTML Living Standard</title>
                  <author fullname="Anne van Kesteren" initials="A." surname="van Kesteren">
                     <organization>Apple Inc.</organization>
                  </author>
                  <date day="11" month="August" year="2026"/>
               </front>
               <annotation>WHATWG</annotation>
            </reference>
            <reference anchor="NAV-TRACKING-MITIGATIONS"
                       target="https://privacycg.github.io/nav-tracking-mitigations/">
               <front>
                  <title>Navigational-Tracking Mitigations</title>
                  <author fullname="Pete Snyder" initials="P." surname="Snyder">
                     <organization>Brave Software, Inc.</organization>
                  </author>
                  <author fullname="Jeffrey Yasskin" initials="J." surname="Yasskin">
                     <organization>Google LLC</organization>
                  </author>
                  <date>n.d.</date>
               </front>
               <annotation>W3C Privacy CG</annotation>
            </reference>
            <reference anchor="ORIGIN">
               <front>
                  <title>The Web Origin Concept</title>
                  <author fullname="A. Barth" initials="A." surname="Barth"/>
                  <date month="December" year="2011"/>
               </front>
               <seriesInfo name="RFC" value="6454"/>
               <seriesInfo name="DOI" value="10.17487/RFC6454"/>
            </reference>
            <reference anchor="RFC6943">
               <front>
                  <title>Issues in Identifier Comparison for Security Purposes</title>
                  <author fullname="D. Thaler"
                          initials="D."
                          role="editor"
                          surname="Thaler"/>
                  <date month="May" year="2013"/>
               </front>
               <seriesInfo name="RFC" value="6943"/>
               <seriesInfo name="DOI" value="10.17487/RFC6943"/>
            </reference>
            <reference anchor="RFC8126">
               <front>
                  <title>Guidelines for Writing an IANA Considerations Section in RFCs</title>
                  <author fullname="M. Cotton" initials="M." surname="Cotton"/>
                  <author fullname="B. Leiba" initials="B." surname="Leiba"/>
                  <author fullname="T. Narten" initials="T." surname="Narten"/>
                  <date month="June" year="2017"/>
               </front>
               <seriesInfo name="BCP" value="26"/>
               <seriesInfo name="RFC" value="8126"/>
               <seriesInfo name="DOI" value="10.17487/RFC8126"/>
            </reference>
         </references>
      </references>
      <?line 510?>
      <section anchor="acknowledgments" numbered="false">
         <name>Acknowledgments</name>
         <t>This document benefited from valuable reviews and suggestions by:</t>
         <ul spacing="normal">
            <li>
               <t>Adam Rice</t>
            </li>
            <li>
               <t>Julian Reschke</t>
            </li>
            <li>
               <t>Kevin McNee</t>
            </li>
            <li>
               <t>Liviu Tinta</t>
            </li>
            <li>
               <t>Mark Nottingham</t>
            </li>
            <li>
               <t>Martin Thomson</t>
            </li>
            <li>
               <t>Valentin Gosu</t>
            </li>
         </ul>
      </section>
   </back>
</rfc>
