Re: [whatwg/fetch] CORS should not be enforced on cross-origin requests where credentials is omit or same-origin (#787)

well that's good to know!

The UX issue, is still a big problem in my mind. We're basically asking every site on the web to add an `Access-Control` header _except_ open-access intranet sites and IP-authentication sites (and even they should probably add it restrict it to their own domain in order to be safe).

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/787#issuecomment-413534599

Received on Thursday, 16 August 2018 12:51:58 UTC