Re: [whatwg/fetch] Drop developer-controlled Authorization header on cross-origin redirects (#944)

It [seems that](https://stackoverflow.com/questions/71311305/how-to-prevent-safari-from-dropping-the-authorization-header-when-following-a-sa) Safari drops `Authorization` on the first redirect (whatever the origins involved), which suggests this is feasible.

@yutakahirano @youennf @ddragana thoughts?

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/944#issuecomment-1056959223
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/944/1056959223@github.com>

Received on Wednesday, 2 March 2022 13:57:35 UTC