Re: [whatwg/fetch] Accept 'sec-'-prefixed headers as CORS-safelisted. (#1000)

Up to a point, part of the reason for the limit is to avoid hitting server limits. If user agents add a lot of `Sec-` headers, or they get attacker-controlled values, we're back to square one. So I don't think it's that easy unfortunately.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/1000#issuecomment-598789833

Received on Friday, 13 March 2020 15:51:15 UTC