Re: [whatwg/fetch] Allowed header in CORS with Access-Control-Expose-Headers (#369)

Safelisted request headers don't depend on the response. I think you're confusing this with https://fetch.spec.whatwg.org/#cors-safelisted-response-header-name which already takes that header into account.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/369#issuecomment-240020991

Received on Tuesday, 16 August 2016 07:10:27 UTC