Re: [whatwg/fetch] Editorial: using serialized origin in TAO check and "null" (Issue #1421)

> This doesn't seem editorial and I'm also not entirely sure why this is wrong. CORS works the same way.
Not wrong as in, `Timing-Allow-Origin: origin-a.com, null` is valid for redirect-tainted requests? That's surprising to me. If that's the case it should be better WPT-covered.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1421#issuecomment-1088620062
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/1421/1088620062@github.com>

Received on Tuesday, 5 April 2022 12:04:11 UTC