Re: [whatwg/fetch] COEP:credentialless and the HTTP cache. (#1253)

@sleevi I don't understand what you mean by "HTTP semantics point of view". All I'm saying is that if C can tell it's cached it's a security problem that NPK addresses, except in the face of local caching proxies (no concrete research on this, but seems likely). And that if we care about local caching proxies for credentials we should also care about them for NPK.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1253#issuecomment-894182203

Received on Friday, 6 August 2021 11:02:13 UTC