- From: Anne van Kesteren <notifications@github.com>
- Date: Fri, 17 Feb 2023 00:19:25 -0800
- To: whatwg/xhr <xhr@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Friday, 17 February 2023 08:19:38 UTC
Could an attacker just not make the request to their own server if they have access to the object? That would be harder with `fetch()`, especially if you don't make `Headers` objects. But there's also service workers to consider, Spectre, etc. Anyway, overall this feels more like a question suitable for Stack Overflow or https://whatwg.org/chat as it doesn't directly impact this standard. So closing therefore. -- Reply to this email directly or view it on GitHub: https://github.com/whatwg/xhr/issues/369#issuecomment-1434282936 You are receiving this because you are subscribed to this thread. Message ID: <whatwg/xhr/issues/369/1434282936@github.com>
Received on Friday, 17 February 2023 08:19:38 UTC