[CORS] Allow-Access-Request-Method

The spec makes it very succinct in its preflight request steps that
Allow-Access-Request-Method should be sent, always.  However in WebKit and
Firefox I'm observing this header only being sent when there are "author
request headers" being sent in Allow-Access-Request-Headers.  Is the spec
not clear in these steps, or are we all just doing it wrong? :)

Thanks,
Jarred

Received on Thursday, 22 December 2011 04:04:57 UTC