Re: [whatwg/fetch] CORS: why is Authorization request header forcing preflight? (#770)

@sleevi This is essentially correct, but it's NOT a workaround for ITP - it's the whole point of OAuth2. My point is that `Authorization` header is part of OAuth2 spec, but it's rendered mostly unusable due to preflight restrictions.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/770#issuecomment-400153316

Received on Tuesday, 26 June 2018 02:04:52 UTC