Re: [w3c/manifest] Explicitly block opaque origins from requesting manifests (#638)

Thanks! Opaque origins are pretty well defined in the HTML spec - e.g. <iframe sandbox> and Content-Security-Policy: sandbox. They're for cases where the frame is explicitly opted into having an opaque origin (i.e. only same-origin with itself).

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/manifest/pull/638#issuecomment-358538533

Received on Thursday, 18 January 2018 05:03:02 UTC