Re: [whatwg/fetch] CORS-safelisted request headers should be restricted according to RFC 7231 (#382)

I did not see https://github.com/whatwg/fetch/issues/313. My GitHub account was set up with an old email address which is why I didn't react on the ping in June. Sorry about that.

As for risk of breakage, yes, things will break. That's why we want to do this in a coordinated way.

>From what I hear the decision to field-content token production for these headers was never really specified.

Should we have the security discussion here or in https://github.com/whatwg/fetch/issues/313?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/382#issuecomment-245340184

Received on Wednesday, 7 September 2016 16:34:41 UTC