Re: [whatwg/fetch] Allow custom headers on no-cors requests (#380)

@annevk Can you please provide any examples where an attacker could achieve that with request headers? Also, wouldn't it work in case of `cors` or `same-origin` modes as well?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/380#issuecomment-244317390

Received on Friday, 2 September 2016 08:40:30 UTC