Re: [whatwg/fetch] If a resource allows credentials but omits Vary, shouldn't responses to non-CORS requests also contain Access-Control-Allow-Credentials? (Issue #1601)

@annevk 

> Perhaps we should update this advice to talk about the Sec-Fetch-Mode request header instead.

What do you have in mind?



-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1601#issuecomment-1901912221
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/1601/1901912221@github.com>

Received on Saturday, 20 January 2024 08:06:52 UTC