Re: [fetch] `user-agent` header control (#37)

One note about my context maybe: 

Right now, for penetration tests, we use malformed UA strings to aim for persistent XSS or Intranet XSS. Giving an attacker control over the UA string via `fetch()` opens the door to abuse that in a CSRF scenario and beyondd. Not sure if that is a good idea. Thus my question, if you consider that to be in scope or not.

Reply to this email directly or view it on GitHub:

Received on Tuesday, 7 April 2015 11:17:28 UTC