Re: [whatwg/fetch] Remove Authorization header upon cross-origin redirect (PR #1544)

If I understand correctly, this only affects Authorization headers that were set by JS, and not cached credentials?

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/1544#issuecomment-1327085536
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/pull/1544/c1327085536@github.com>

Received on Friday, 25 November 2022 06:52:57 UTC