Re: [whatwg/fetch] Proposal: Allow servers to take full responsibility for cross-origin access protection (#878)

> I could see a TLS-level assertion that the server is basically open to all kinds of connections/requests and is able to protect itself as a thing that might be workable: [quicwg/base-drafts#1993](https://github.com/quicwg/base-drafts/issues/1993).

That is a very interesting direction indeed; opens up some possibilities.

> For CORS itself it seems worthwhile to wait on how Origin Policy/Manifest works out.

Origin Policy is definitely another interesting direction. However, currently, the `Bypass` mode still seems very restricted (https://wicg.github.io/origin-policy/#fetch-bypass-preflight), so might not address the above use cases.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/878#issuecomment-471550326

Received on Monday, 11 March 2019 14:02:15 UTC