-
Notifications
You must be signed in to change notification settings - Fork 381
Closed
Labels
addition/proposalNew features or enhancementsNew features or enhancementsneeds testsMoving the issue forward requires someone to write testsMoving the issue forward requires someone to write tests
Description
(From the mailing list.)
With the given state of the standard, it is impossible to design APIs that use redirection on authenticated resources and allow access by clients implementing the standard.
The reason for this is that redirects on preflight CORS requests are generally forbidden. An older version of the standard says
7.1.5 Cross-Origin Request with Preflight
If the response has an HTTP status code that is not in the 2xx range
Apply the network error steps.
I cannot find this passage in the latest revision, but it's perhaps been rephrased. (Am I right?)
This restriction seems too strict as it disallows valid (RESTful) use patterns.
Opinions?
Metadata
Metadata
Assignees
Labels
addition/proposalNew features or enhancementsNew features or enhancementsneeds testsMoving the issue forward requires someone to write testsMoving the issue forward requires someone to write tests