Re: [whatwg/fetch] CORS protocol and HTTP caches (#402)

> does it mean to allow sending credentials and cookies with the request?

Yeah. So I think varying on that for the cache is still sufficient as only without that do you get an actual security issue. And recommending `Vary` for the remainder. Thanks.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/402#issuecomment-257513618

Received on Tuesday, 1 November 2016 08:33:43 UTC