Re: [whatwg/fetch] Should we send an Origin header for no-cors fetches? (#225)

Also note that discussion in https://github.com/w3c/resource-timing/issues/64 to make `Origin` exclusive for CORS and introduce a new header for CSRF defense.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/225#issuecomment-239387981

Received on Friday, 12 August 2016 08:17:20 UTC