Re: [whatwg/fetch] CORS: why is Authorization request header forcing preflight? (#770)

@sleevi here's another good example of misconnect. See OpenID connect spec: http://openid.net/specs/openid-connect-core-1_0.html#UserInfo section 5.3. It goes to directly describe requirements for Authorization header use and CORS support.



-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/770#issuecomment-399618974

Received on Saturday, 23 June 2018 01:11:23 UTC