Re: [fetch] Add new Access-Control-Suppress-Headers CORS response header (#253)

@roryhewitt you can't do that with someone else their cookies. I recommend studying https://annevankesteren.nl/2015/02/same-origin-policy.

I agree with @sicking that a big concern with exclude would be that it's not backwards compatible.

Therefore, it's probably best not to add this. #252 exists for expanding expose, so closing this.

---
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/253#issuecomment-201222878

Received on Friday, 25 March 2016 09:45:39 UTC