Re: [whatwg/fetch] Enforce CORP on "navigate" request mode (#1113)

See the discussion at https://github.com/whatwg/fetch/issues/687#issuecomment-390124209. I'm not sure that's worth revisiting.

I think it makes sense to enforce XFO for redirects. HTML doesn't do that currently, but that could be changed. I'm not entirely sure I understand the analysis in the Chromium bug. Is the assumption that all those redirects do not want to be blocked? Why?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1113#issuecomment-722239289

Received on Thursday, 5 November 2020 08:57:32 UTC