Re: [whatwg/fetch] CORS should not be enforced on cross-origin requests where credentials is omit or same-origin (#787)

Ah, I'm sorry, I didn't know of the association.

What I am saying, is that the odds are _greater_ that a security vulnerability is created by a server-administrator incorrectly implementing CORS, than they are of the security vulnerability of a completely open intranet site.

In my mind, you're choosing the greater vulnerability of the two. I understand that you don't agree with that, but I think it's worth considering that perhaps browsers have _already_ implemented a security regression and it would be better to _stop_ that regression.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/787#issuecomment-413276742

Received on Wednesday, 15 August 2018 17:43:07 UTC