Re: [whatwg/fetch] Document CORS safelist exceptions (#621)

@annevk addressed your suggestions, PTAL. Do we want to expand more on what should be involved in introducing a new exception (e.g. consideration for how much the attacker controls the request body and other headers, the uniqueness of the Content-Type value, etc.)?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/621#issuecomment-340050196

Received on Friday, 27 October 2017 18:31:58 UTC