Re: [whatwg/fetch] Recommend that servers follow the steps of CORS preflight for easier troubleshooting (Issue #1588)

The tradeoff here is that you end up giving more information to potential attackers. What is best in any given situation is not something we can make a universal statement about I think.

With regards to the timing channel, that is mainly for non-preflight responses, though perhaps attackers can also learn something from the amount of time it takes to grant or deny access to a particular request.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1588#issuecomment-1727234863
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/1588/1727234863@github.com>

Received on Wednesday, 20 September 2023 08:33:32 UTC