Re: [fetch] CSP Request Header and CORS preflight fetch. (#52)

Hmm, well.. The CH spec does [specify the BNF for each header](http://httpwg.org/http-extensions/client-hints.html#rfc.section.3). It doesn't seem like a far stretch to make UA require a validation step for the provided values?

---
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/52#issuecomment-186471591

Received on Saturday, 20 February 2016 00:59:18 UTC