Re: [whatwg/fetch] CORS: arbitrary blocking of accept header based on length (#862)

I'm not sure why you think it's usually quite large? It's usually `*/*` or some such, definitely not exceeding 1024 bytes. Also, no, as long as the bytes are attacker-controlled they are problematic and shouldn't exceed certain limits.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/862#issuecomment-458161682

Received on Monday, 28 January 2019 14:52:58 UTC