(See http://www.chromium.org/blink#launch-process for an overview)
Change description:
We'll begin requiring servers on a user's machine (127.0.0.1) or intranet (as defined by RFC1918) to explicitly opt-in to connections originating from the public internet.
Changes to API surface:
Two new CORS headers, and more preflights.
Links:
Public standards discussion: https://mikewest.github.io/cors-rfc1918/
Support in other browsers:
Basically zero discussion so far.
Comment 1 by mkwst@chromium.org
, Feb 29 2016