Re: [whatwg/fetch] Proposal: Allow servers to take full responsibility for cross-origin access protection (#878)

> My proposal/request is exactly to be immune from such issues

This guarantee cannot be made. If a vulnerability is discovered that puts real users at risk, browsers will fix that to protect users.

If the spec doesn't update, then the spec won't reflect reality.

If a browser doesn't update, users and competitors will accuse that browser of having security issues.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/878#issuecomment-471001339

Received on Friday, 8 March 2019 17:03:42 UTC