w3c / webappsec-fetch-metadata

Fetch Metadata
https://w3c.github.io/webappsec-fetch-metadata/
Other
75 stars 28 forks source link

Sec-Fetch-Site's scheme comparison should account for opaque origins. #42

Closed mikewest closed 5 years ago

mikewest commented 5 years ago

Thanks, @annevk. Closes #41.

mikewest commented 5 years ago

WDYT, @annevk?

annevk commented 5 years ago

Seems better, though dot usage is inconsistent.

I think you still want to use https://url.spec.whatwg.org/#host-same-site as there's a number of cases this doesn't consider, such as IP addresses.

mikewest commented 5 years ago

Right on both counts. Thanks!