Re: [whatwg/fetch] Cross-Origin Read Blocking (CORB) (#681)

https://github.com/whatwg/fetch/issues/144#issuecomment-368040980 - see "Attack 4".

It looks like CORB will handle this attack for particular mime types, but I think it still makes sense to apply the extra blocking I proposed, since it'll cover all mime types.

Let me know if that's wrong.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/681#issuecomment-378617686

Received on Wednesday, 4 April 2018 14:23:44 UTC