- From: Mark S. Miller <erights@google.com>
- Date: Thu, 17 Dec 2009 13:24:56 -0800
- To: public-webapps <public-webapps@w3.org>
Received on Thursday, 17 December 2009 21:28:29 UTC
Despite the costs of doing preflight opt-in on a per-resource basis rather than a per-origin basis, to meet its security goals, CORS proposes to do preflight on a per-resource basis. I have seen the rationale for this stated in bits and pieces. Can anyone point me at a reasonably self contained statement for why we need preflight on a per-resource rather than a per-origin basis? If there's nothing adequate to point at, could someone state a reasonably self contained rationale for this? Thanks. -- Cheers, --MarkM
Received on Thursday, 17 December 2009 21:28:29 UTC