- From: sleevi <notifications@github.com>
- Date: Wed, 28 Mar 2018 02:34:40 +0000 (UTC)
- To: whatwg/fetch <fetch@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Wednesday, 28 March 2018 02:35:05 UTC
That’s not the purpose of the credentials flag in CORS though - it’s to prevent ambient identity from being misused. In that regard, it doesn’t count, unless someone treats the Token ID itself as a bearer token, and that’s arguably the exact opposite intent of TB. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/whatwg/fetch/pull/325#issuecomment-376740525
Received on Wednesday, 28 March 2018 02:35:05 UTC