No default withCredentials. Updated version of #47#53
No default withCredentials. Updated version of #47#53gsf wants to merge 1 commit intobrowserify:masterfrom
Conversation
|
I think it is a bad idea to change the default on such an important flag without a major version bump, or at least minor. Though I would say if this was a fresh project that withCredentials should be false by default. |
|
As discussed at naugtur/xhr#33 (click "Show outdated diff"), some believe the withCredentials default in the spec was a mistake, as was the Access-Control-Allow-Origin wildcard. I haven't found many resources to back this up, however. The commented text at http://enable-cors.org/server_nginx.html suggests this, but others (including http://fetch.spec.whatwg.org/#basic-safe-cors-protocol-setup) seem to favor the wildcard and the default of false. |
|
I would like to see this merged since Resources examples: |
|
Please merge. The current default behavior is totally unexpected. |
|
Holy shit, please merge. That took me forever to figure out. |
|
Any update on if/when this will get merged? |
Any reason to alter the default for xhr.withCredentials?