From 8a974e246560f859c1c1e2c71b5a26df1663784c Mon Sep 17 00:00:00 2001
From: Arthur Sonzogni
Date: Mon, 20 Sep 2021 15:15:25 +0200
Subject: [PATCH] Address annevk@ comment about redirects.
---
fetch.bs | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fetch.bs b/fetch.bs
index d169d7411..5446b42c4 100644
--- a/fetch.bs
+++ b/fetch.bs
@@ -1905,7 +1905,8 @@ source of security bugs. Please seek security review for features that deal with
is not "credentialless
", return true.
If request's origin is same origin with
- request's current URL's origin, return true.
+ request's current URL's origin and
+ request's tainted origin flag is not set, return true.
Return false.