Re: [whatwg/fetch] Block 'ftp:' requests from non-'ftp:' clients. (#464)

mikewest commented on this pull request.



> @@ -2407,6 +2407,14 @@ with a <i>CORS flag</i> and <i>recursive flag</i>, run these steps:
   have it expose less sensitive information.
 
  <li>
+  <p>If <var>request</var>'s <a for=request>current URL</a>'s <a for=url>scheme</a> is
+  "<code>ftp</code>" and <var>request</var>'s <a for=request>client</a>'s
+  <a for=environment>creation URL</a>'s <a for=url>scheme</a> is not "<code>ftp</code>",
+  and <var>request</var>'s <a for=request>reserved client</a> is either <code>null</code>
+  or an <a>environment</a> whose <a for=environment>target browsing context</a> is a
+  <a>nested browsing context</a>, set <var>response</var> to a <a>network error</a>.

Done and done.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/464

Received on Wednesday, 8 February 2017 11:06:32 UTC