Re: [whatwg/fetch] If a resource allows credentials but omits Vary, shouldn't responses to non-CORS requests also contain Access-Control-Allow-Credentials? (Issue #1601)

@annevk Wouldn't it be premature? My understanding is that [Fetch Metadata](https://w3c.github.io/webappsec-fetch-metadata/) will [eventually](https://fetch.spec.whatwg.org/#goals) get merged into the Fetch standard. Correct? Until then, though, I'm not sure the Fetch standard should reference Fetch Metadata Request Headers like `Sec-Fetch-Mode`.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1601#issuecomment-1420875563
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/1601/1420875563@github.com>

Received on Tuesday, 7 February 2023 14:33:53 UTC