Re: [fetch] Update Access-Control-Allow-Headers CORS response header to allow * (allow-all) (#251)

@sicking, well the last thing I want is for this to get bogged down (even if it's my doing). So I will back off on trying to get _everything_ I want, and will defer to you on this.

If we agree to allow `Access-Control-Allow-Headers: *`, `Access-Control-Allow-Methods: *` (and potentially `Access-Control-Expose-Headers: *`?) on non-credentialed requests only (which seems to be pretty much a consensus), how do we go about allowing that (adding it to the spec and getting buy-in for any other parties)?

---
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/251#issuecomment-201070935

Received on Thursday, 24 March 2016 23:24:51 UTC