この仕様では、次のような場所から返されるURIのusername:passwordをどうするかについては言及されていません。
Location: http://user:secret@w3.org/hidden/pages
私たちはそのようなことを無視することになっていますか?それは意味をなさないようですが、それが起こったらどうなるのだろうと思っていました(つまり、サーバーの設定ミス、管理者/プログラマーからの奇妙なアイデア...)
14.30 Location
The Location response-header field is used to redirect the recipient
to a location other than the Request-URI for completion of the request
or identification of a new resource. For 201 (Created) responses, the
Location is that of the new resource which was created by the request.
For 3xx responses, the location SHOULD indicate the server's preferred
URI for automatic redirection to the resource. The field value
consists of a single absolute URI.
Location = "Location" ":" absoluteURI
An example is:
Location: http://www.w3.org/pub/WWW/People.html
Note: The Content-Location header field (section 14.14) differs
from Location in that the Content-Location identifies the original
location of the entity enclosed in the request. It is therefore
possible for a response to contain header fields for both Location
and Content-Location. Also see section 13.10 for cache
requirements of some methods.