Re: [whatwg/fetch] CORS: arbitrary blocking of accept header based on length (#862)

To me the currently implemented approach seems wrong as it breaks existing webapps. Suggestion 2 seems to keep your security measures and would not break these existing webapps.

What part of 2 is wrong in your opinion?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/862#issuecomment-458548495

Received on Tuesday, 29 January 2019 13:57:06 UTC