Re: [whatwg/fetch] Proposal: Allow servers to take full responsibility for cross-origin access protection (#878)

I don't think any solution can be final. If you invent yet another opt-in, say `Allow-Superpowers-And-I-Really-Mean-It: honestly`, and 5 years later a new capability is released that would create a vulnerability on 5% of those opt-in sites, you then need yet another opt-in.

The CORS change seems bad, but I don't see yet another opt-in making things easier. Another opt-in has the same server-updating problem.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/878#issuecomment-470979571

Received on Friday, 8 March 2019 16:02:14 UTC