Re: [whatwg/fetch] Drop developer-controlled Authorization header on cross-origin redirects (#944)

> It [seems that](https://stackoverflow.com/questions/71311305/how-to-prevent-safari-from-dropping-the-authorization-header-when-following-a-sa) Safari drops Authorization on the first redirect (whatever the origins involved), which suggests this is feasible.

Do you mean removing `authorization` on every redirect by "this"? Or do you mean removing it only on cross-origin redirects?

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/944#issuecomment-1075168408
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/944/1075168408@github.com>

Received on Tuesday, 22 March 2022 13:17:38 UTC