Re: [fetch] `user-agent` header control (#37)

Hi all,

despite the discussion having progressed a lot already, do you consider XSS or CRSF-to-XSS via UA string in scope for the spec? Or would that be something, the implementers have to take care of on their own?

Cheers,
.mario

P.S. @mathiasbynens You are faster than light :D

---
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/37#issuecomment-90509025

Received on Tuesday, 7 April 2015 11:14:00 UTC