[Bug 21203] EME leaks information cross-origin

https://www.w3.org/Bugs/Public/show_bug.cgi?id=21203

--- Comment #25 from David Dorwin <ddorwin@google.com> ---
The application provides the initData, which contains the defaultURL (if any),
and the application will send the keymessage to the server (either its own or
the one specified by defaultURL). Ultimately, it is the application that is
sending the information, which it already had access to, and normal CORS rules
should apply, right?

-- 
You are receiving this mail because:
You are the QA Contact for the bug.

Received on Saturday, 26 October 2013 04:14:07 UTC