Re: [whatwg/fetch] Privacy-preserving HSTS (#920)

@johnwilander I have another question. If I navigate to `example.com` and that embeds `elsewhere.invalid` in a frame. Both attempt to set HSTS, does only `example.com` succeed?

The blog post focuses primarily on subdomains which throws me off a bit.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/920#issuecomment-630314473

Received on Monday, 18 May 2020 17:02:44 UTC