From 8a974e246560f859c1c1e2c71b5a26df1663784c Mon Sep 17 00:00:00 2001 From: Arthur Sonzogni Date: Mon, 20 Sep 2021 15:15:25 +0200 Subject: [PATCH] Address annevk@ comment about redirects. --- fetch.bs | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/fetch.bs b/fetch.bs index d169d7411..5446b42c4 100644 --- a/fetch.bs +++ b/fetch.bs @@ -1905,7 +1905,8 @@ source of security bugs. Please seek security review for features that deal with is not "credentialless", return true.

  • If request's origin is same origin with - request's current URL's origin, return true.

    + request's current URL's origin and + request's tainted origin flag is not set, return true.

  • Return false.