Re: [whatwg/fetch] Header to opt out of opaque redirect (#601)

@SampsonCrowley I understand this space initimately, having been building web systems for large financials for over 25 years and I take security very seriously.  Please don't make assumptions.  We already have plenty of "pre-flight" checks, this is just a post-flight check.

As I said, we worked around the problem by avoiding the 30x response codes.  Unfortunately the landscape is getting worse with the most popular JS frameworks coalescing around fetch under the hood.



-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/601#issuecomment-1427665425
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/601/1427665425@github.com>

Received on Monday, 13 February 2023 10:08:30 UTC