[whatwg/fetch] Strengthen requirements on CORS-safelisted request-headers (#736)

This should reduce the attack surface of non-preflighted requests quite a bit.

Fixes #382. Closes #313.
You can view, comment on, or merge this pull request online at:

  https://github.com/whatwg/fetch/pull/736

-- Commit Summary --

  * Strengthen requirements on CORS-safelisted request-headers

-- File Changes --

    M fetch.bs (68)

-- Patch Links --

https://github.com/whatwg/fetch/pull/736.patch
https://github.com/whatwg/fetch/pull/736.diff

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/736

Received on Friday, 25 May 2018 09:20:11 UTC