Re: [w3c/webpayments-payment-apps-api] Payment apps and methods, are they the same? (#35)

> Yep, if ~bob has that degree of server control he can do that. We're only protecting static servers.

I have to say that feels a bit scary. Maybe I am being naive but are there other ways that allowing a user to specify headers in a response effectively gives them control of the origin?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/webpayments-payment-apps-api/issues/35#issuecomment-247069814

Received on Wednesday, 14 September 2016 16:22:43 UTC