Re: [whatwg/fetch] CORS should not be enforced on cross-origin requests where credentials is omit or same-origin (#787)

_[citation needed]_

That assumes that hundrds of millions of people use a site behind a firewall that has absolutely no other protections.

I have yet to see a site like that. Every intranet site I've used (at a Fortune 500 company) have not only been restricted to to the firewall, but _also_ have had some sort of employee authentication system.

I have no idea how this could be measured, but from my experience, this is a non-issue. If you allow anyone who has access to your network to have access to your intranet site, that means anyone could come into your physical location, use an open Ethernet port and take all of the data off of the intranet site... that's a huge security risk that most organizations are not going to take.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/787#issuecomment-413242793

Received on Wednesday, 15 August 2018 15:56:41 UTC