Re: [whatwg/fetch] Listing headers safe only for certain values is a bad idea (#313)

> banning almost all all kind of cross-site ...

Looks I said too much.

I'm not sure how much overlap there would between things to block and things useful for some people.

E.g. limiting content-type to be valid `media-type` wouldn't hurt any good usage.

So, I'd change my opinion to about increase of complexity and effectiveness. As I said in the last 2 comments, I'm not sure about effectiveness of current CORS preflight.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/313#issuecomment-245553796

Received on Thursday, 8 September 2016 10:11:58 UTC