Re: [whatwg/xhr] XHR: how can I read request headers? (Issue #369)

Could an attacker just not make the request to their own server if they have access to the object?

That would be harder with `fetch()`, especially if you don't make `Headers` objects.

But there's also service workers to consider, Spectre, etc.

Anyway, overall this feels more like a question suitable for Stack Overflow or https://whatwg.org/chat as it doesn't directly impact this standard. So closing therefore.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/xhr/issues/369#issuecomment-1434282936
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/xhr/issues/369/1434282936@github.com>

Received on Friday, 17 February 2023 08:19:38 UTC