- From: Jake Archibald <notifications@github.com>
- Date: Fri, 08 Mar 2019 08:01:47 -0800
- To: whatwg/fetch <fetch@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Friday, 8 March 2019 16:02:14 UTC
I don't think any solution can be final. If you invent yet another opt-in, say `Allow-Superpowers-And-I-Really-Mean-It: honestly`, and 5 years later a new capability is released that would create a vulnerability on 5% of those opt-in sites, you then need yet another opt-in. The CORS change seems bad, but I don't see yet another opt-in making things easier. Another opt-in has the same server-updating problem. -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/whatwg/fetch/issues/878#issuecomment-470979571
Received on Friday, 8 March 2019 16:02:14 UTC