Re: [whatwg/fetch] CORS: why is Authorization request header forcing preflight? (#770)

I'm inclined to close this as we cannot allow distributed dictionary attacks and we've already had trouble enough with the headers that you are allowed to preflight.

It sounds like the problem here is primarily one of OpenID/OAuth figuring out what their ideal setup and having conformance tests and such for that (and maybe providing slightly more detailed documentation on how to implement the protocol).

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/770#issuecomment-399654795

Received on Saturday, 23 June 2018 09:01:05 UTC