Re: [whatwg/fetch] Strengthen requirements on CORS-safelisted request-headers (#736)

@johnwilander @mikewest @ckerschb @bzbarsky I'd appreciate your review. @sicking this goes against what you advocated for in #313, but given Safari's success in locking this down and given that there continue to be security bugs in this area due to it not being locked down I think this is the responsible path forward.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/736#issuecomment-391995034

Received on Friday, 25 May 2018 09:22:26 UTC