- From: Adrian Hope-Bailie <notifications@github.com>
- Date: Wed, 14 Sep 2016 09:22:00 -0700
- To: w3c/webpayments-payment-apps-api <webpayments-payment-apps-api@noreply.github.com>
Received on Wednesday, 14 September 2016 16:22:43 UTC
> Yep, if ~bob has that degree of server control he can do that. We're only protecting static servers. I have to say that feels a bit scary. Maybe I am being naive but are there other ways that allowing a user to specify headers in a response effectively gives them control of the origin? -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/w3c/webpayments-payment-apps-api/issues/35#issuecomment-247069814
Received on Wednesday, 14 September 2016 16:22:43 UTC