Re: [whatwg/fetch] CORS safelisting trace context header (#911)

Exceptions are based on capabilities of existing features, primarily `<form>`. A couple headers were added out of naivety. Basically extensions of this list should not happen as they put end user security at risk.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/911#issuecomment-512258000

Received on Wednesday, 17 July 2019 13:38:08 UTC