Re: [whatwg/fetch] Cross-Origin Read Blocking (CORB) (#681)

Why does CORB blocking filter the response? Wouldn't it be more robust to replace the response with a generic empty response?

Although they're less sensitive, CORS safelisted headers and status codes also leak data.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/681#issuecomment-380061285

Received on Tuesday, 10 April 2018 11:08:59 UTC