Re: [fetch] RFC: a mechanism to bypass CORS preflight (#210)

Yeah. For origins where there are multiple administrators/authors/apps, this is entirely sensible; it's just really annoying for single-party origins (which tend to get a lot of traffic, so this chattiness matters).

Perhaps if we found a way to limit it to them, it would be viable. Not sure how to do that, though.

In the meantime, we could spec up non-credentialed server-wide opt-in, leaving credentials to future extensions.

---
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/210#issuecomment-179539017

Received on Wednesday, 3 February 2016 23:55:57 UTC