Re: [whatwg/fetch] If a resource allows credentials but omits Vary, shouldn't responses to non-CORS requests also contain Access-Control-Allow-Credentials? (Issue #1601)

I think most of the section would have to be rewritten around `Vary: Sec-Fetch-Mode` as opposed to `Vary: Origin`. And it would probably also have to be run past some people deploying this kind of thing on a large scale.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/1601#issuecomment-2573279388
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/1601/2573279388@github.com>

Received on Monday, 6 January 2025 14:55:26 UTC