Re: [whatwg/fetch] Vary HTTP cache on credentials mode (#307)

@annevk I'm still struggling to understand why it's "unsafe", at least with respect to the fact that the cached entry has `Access-Control-Allow-Origin: *`

For the sake of my own stupidity, could you maybe illustrate a request/response pair (or set of) that you think would be affected, and highlight where you think the site operator doesn't already have a sufficient degree of control?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/307#issuecomment-285105570

Received on Wednesday, 8 March 2017 17:18:17 UTC