You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ACAO does not allow credentials to be used for value '*'. There is no similar constraint for TAO.
The Origin header might not always be set in a given request so this makes it harder to always provide a specific information for TAO in the response.
That said, servers using '' might be at bigger risk, say in case of no-cors/credential loads.
Should '' use be forbidden in case of credentials? Should there be wording in the spec discouraging to use '*'?
The text was updated successfully, but these errors were encountered:
ACAO does not allow credentials to be used for value '*'. There is no similar constraint for TAO.
The Origin header might not always be set in a given request so this makes it harder to always provide a specific information for TAO in the response.
That said, servers using '' might be at bigger risk, say in case of no-cors/credential loads.
Should '' use be forbidden in case of credentials? Should there be wording in the spec discouraging to use '*'?
The text was updated successfully, but these errors were encountered: