Re: [whatwg/fetch] Send "null" Origin headers on cross-origin requests from an RFC7686 address (Issue #1350)

I'm happy to file implementation bugs and work on the tests, but before that, I'd like to know whether that's a change that Chrome and Firefox (others?) would be willing to make. (I would also be happy to work on upstreaming the Brave changes to Chromium.)

Is @mikewest 's suggestion (only touching `no-cors`) what folks think should be done? Is this something I should bring up at the next WebAppSec teleconf?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1350#issuecomment-972488706

Received on Thursday, 18 November 2021 03:35:58 UTC