- From: Anne van Kesteren <notifications@github.com>
- Date: Tue, 23 Aug 2016 06:22:36 -0700
- To: whatwg/fetch <fetch@noreply.github.com>
Received on Tuesday, 23 August 2016 13:23:10 UTC
@tyoshino any updates? See also the discussion with @igrigorik in https://github.com/w3c/resource-timing/issues/64. It might actually be good to just restrict `Origin` to CORS exclusively and if we need something beyond same-site cookies to introduce a new header specifically for that purpose. It's not clear to me that the dual purpose of `Origin` for CORS and somewhat anti-CSRF but not really is beneficial. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/whatwg/fetch/issues/225#issuecomment-241728122
Received on Tuesday, 23 August 2016 13:23:10 UTC