Re: [whatwg/fetch] Authorization-removal change was compatibility-breaking (Issue #1631)

In non-server environments you could not rely on this behavior so there it is not considered a breaking change. I could imagine offering an option to preserve the header though, even when there's a cross-origin redirect.

Thought `--location-trusted` might imply that it's only preserved for a single hop? That sounds a bit iffy given that we try to treat redirects identical.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1631#issuecomment-1512566628
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/1631/1512566628@github.com>

Received on Tuesday, 18 April 2023 07:15:35 UTC