Re: [whatwg/fetch] Update Fetch to support Token Binding. (#325)

I guess the real question is not whether TB message is a credential or not (which I maintain it isn't:)), but whether it should be sent in the contexts where the sending of cookies is suppressed for anonymization/privacy reasons. When bound cookies are not being sent, I think there is no reason to send TB messages. Do folks agree with this assessment?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/325#issuecomment-376981196

Received on Wednesday, 28 March 2018 18:06:18 UTC