Re: [w3c/ServiceWorker] Service workers allow for more responses to be executed as script (#1509)

Yeah, it wouldn't help with the couple of headers the attacker gets to control, but method is a lot more significant and it seems somewhat reasonable to declare the headers out-of-scope.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/ServiceWorker/issues/1509#issuecomment-965239733

Received on Wednesday, 10 November 2021 14:15:07 UTC