Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TAO is not fully aligned with ACAO #63

Closed
youennf opened this issue Jan 29, 2019 · 2 comments
Closed

TAO is not fully aligned with ACAO #63

youennf opened this issue Jan 29, 2019 · 2 comments

Comments

@youennf
Copy link

youennf commented Jan 29, 2019

ACAO does not allow credentials to be used for value '*'. There is no similar constraint for TAO.
The Origin header might not always be set in a given request so this makes it harder to always provide a specific information for TAO in the response.

That said, servers using '' might be at bigger risk, say in case of no-cors/credential loads.
Should '
' use be forbidden in case of credentials? Should there be wording in the spec discouraging to use '*'?

@yoavweiss
Copy link
Contributor

This sounds highly related to w3c/resource-timing#178 and not necessarily Server Timing specific. Is that correct?

@youennf
Copy link
Author

youennf commented Jan 31, 2019

Oh right, it should be a resource-timing issue not a server timing one.
Let's close this one then.

@youennf youennf closed this as completed Jan 31, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants