Need to support Cross-Origin-Resource-Policy (aka CORP; was: From-Origin) header as CORB opt-in |
||||
Issue descriptionhttps://github.com/whatwg/fetch/issues/687 proposes to use From-Origin header to protect responses against Spectre attacks. We should consider using this header as a signal to protect the response in CORB (even if it is not HTML, XML or JSON but something like an image).
,
Jun 19 2018
,
Dec 4
,
Jan 15
I'll mark this as a dupe of issue 853723, so that we have one place to track this. |
||||
►
Sign in to add a comment |
||||
Comment 1 by lukasza@chromium.org
, Jun 19 2018