From 5c99ed62486976f9f1098dfada02d809b23693bf Mon Sep 17 00:00:00 2001 From: Yoav Weiss Date: Mon, 18 Mar 2019 15:16:49 +0100 Subject: [PATCH] safelist request headers starting with Sec- --- fetch.bs | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/fetch.bs b/fetch.bs index 70f08d11c..703b5cf7e 100644 --- a/fetch.bs +++ b/fetch.bs @@ -645,8 +645,12 @@ production as
  1. Let value be header's value. -

  2. -

    Byte-lowercase header's name and switch on the result: +

  3. Let lowercase name be the byte-lowercase header's name. + +

  4. If lowercase name starts with `sec-`, return true. + +

  5. Switch on lowercase name:

    `accept`