Skip to content

Possibly incorrect implementation #1

@maletor

Description

@maletor

In the outline for a "participating server", the lack of presence of an Origin header is interpretted as a valid use case (since it is same origin) and the client may modify state on the server. It is only when a Origin header is specified and it does not match the server's whitelist is there a problem.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions