Re: [whatwg/fetch] Document CORS safelist exceptions (#621)

Thanks for starting this. I agree that the discussion isn't quite resolved, but we might as well document this meanwhile and discourage further such deviations.

I think this text is in part normative due to the requirement put on servers (mostly to be aware of it) and therefore I'd suggest we create a new "CORS protocol exceptions" section within the "CORS protocol" section after the "Examples" section, so as 3.2.7., with this text. And perhaps the note you have now could become a simple pointer to that section.

Also, instead of framing it on behalf of browsers, I would suggest saying it's specifications that caused this. And also caution new specifications to not go further down this path (or at least not do so without discussion).

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/621#issuecomment-339906781

Received on Friday, 27 October 2017 08:25:04 UTC