[cors] Should browsers send non-user-controllable headers in Access-Control-Request-Headers?

Chrome sends:

Access-Control-Request-Headers:Origin, Content-Type, Accept

Is that just wrong?

Received on Thursday, 22 December 2011 02:17:30 UTC