Re: [fetch] Request for support for certificate pinning (#98)

Ah, if its scoped to own origin only then that's more reasonable.. I read the proposal as "my app wants to specify pins for origins I depend on". That said, even for same origin, what happens when a third-party script runs on my site? Would it be able to clear and modify pins for my origin.. because that doesn't seem right either.

---
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/98#issuecomment-129970168

Received on Tuesday, 11 August 2015 17:06:33 UTC