mikewest / http-state-tokens

Incrementally better HTTP state management.
https://mikewest.github.io/http-state-tokens/draft-west-http-state-tokens.html
Other
300 stars 8 forks source link

Opt-in and notification #14

Open michael-oneill opened 5 years ago

michael-oneill commented 5 years ago

I agree there should be a user opt-in for this.

If the server increases the default or raises scope from same-origin the user should be notified, and given a chance to refuse.