Re: [whatwg/fetch] Proposal: Allow servers to take full responsibility for cross-origin access protection (#878)

> dozens of Web APIs are running that have followed https://enable-cors.org/ with the intention of working from any Web application. These instructions no longer hold

I don't know the history behind the CORS change. It seems pretty bad that a breaking change was made by this. But, if that change was justified, similar future issues would be a problem for your proposal too.

>> What's your proposal, if not an opt-in?
>
> A mechanism by which a server can say "I am taking care of all current and future cross-origin protections for this resource"

You're describing an opt-in.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/878#issuecomment-470997420

Received on Friday, 8 March 2019 16:52:33 UTC