Re: [whatwg/fetch] Drop developer-controlled Authorization header on cross-origin redirects (#944)

Either, though I'd be somewhat reluctant to remove them same-origin as well. On the flipside, considering this anew it does seem like a weird special case for `Authorization`. It's justifiable, but it doesn't make for a coherent security story.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/944#issuecomment-1075192974
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/944/1075192974@github.com>

Received on Tuesday, 22 March 2022 13:39:48 UTC