Re: [whatwg/fetch] Doc: failed CORS fetch with credentials should ignore Set-Cookie response header (#855)

I only see a risk if the server expects CORS to be more authoritative. But yeah, I guess we should update the standard here (in particular the example mentioned by OP) and caution servers not to expect such things.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/855#issuecomment-451467541

Received on Friday, 4 January 2019 15:01:39 UTC