Re: [whatwg/fetch] Safelist Last-Event-ID (#568)

The other problem is that it can contain essentially any header value byte, which historically has been an attack vector (and is why we have restrictions on the other headers now).

We'd have to apply the same restrictions as with `accept`.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/568#issuecomment-979001883

Received on Thursday, 25 November 2021 09:17:32 UTC