Re: [whatwg/fetch] Allow redirects on cross-origin credentialed requests (#1235)

Well, I have to retract that because I believe one of the `Sec-Fetch-` headers exposes the mode, so they're not identical requests. Sigh.

Still not sure why we can't follow the redirect chain to see if the final request is eligible.

I'll see if I can get the SSO provider to change their stuff. I fully anticipate a bunch of "why do we need to do this" and "this isn't our fault we don't have anything to do with CORS"...

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1235#issuecomment-843376704

Received on Tuesday, 18 May 2021 17:21:03 UTC