- From: Noam Rosenthal <notifications@github.com>
- Date: Tue, 05 Apr 2022 05:03:59 -0700
- To: whatwg/fetch <fetch@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Tuesday, 5 April 2022 12:04:11 UTC
> This doesn't seem editorial and I'm also not entirely sure why this is wrong. CORS works the same way. Not wrong as in, `Timing-Allow-Origin: origin-a.com, null` is valid for redirect-tainted requests? That's surprising to me. If that's the case it should be better WPT-covered. -- Reply to this email directly or view it on GitHub: https://github.com/whatwg/fetch/issues/1421#issuecomment-1088620062 You are receiving this because you are subscribed to this thread. Message ID: <whatwg/fetch/issues/1421/1088620062@github.com>
Received on Tuesday, 5 April 2022 12:04:11 UTC