Re: [whatwg/fetch] Specify the behavior of `COEP: credentialless`, (#1229)

@domenic commented on this pull request.



> @@ -1892,6 +1892,24 @@ source of security bugs. Please seek security review for features that deal with
  <a for="URL serializer"><i>exclude fragment</i></a> set to true.
 </ol>
 
+<p>To check <dfn export>Cross-Origin-Embedder-Policy allows credentials</dfn>, given a <a
+for=/>request</a> <var>request</var>, run theses steps:

Note that this rule differs between whatwg/html and whatwg/fetch :(. We are sorry about that.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/1229#discussion_r653774825

Received on Thursday, 17 June 2021 17:18:04 UTC