Skip to content

Commit

Permalink
Clarify that manifest fetches should not send a Referer (w3c-fedid#239)
Browse files Browse the repository at this point in the history
  • Loading branch information
cbiesinger authored Mar 30, 2022
1 parent 8d1afed commit b439d86
Showing 1 changed file with 3 additions and 2 deletions.
5 changes: 3 additions & 2 deletions spec/index.bs
Original file line number Diff line number Diff line change
Expand Up @@ -579,8 +579,9 @@ by the [=IDP=].

The manifest discovery endpoint is fetched:

(a) **without** cookies and
(b) **with** a special [[#Sec-FedCM-CSRF]] header, and
(a) **without** cookies,
(b) **with** a special [[#Sec-FedCM-CSRF]] header,
(c) **without** a [[RFC7231#header.referer|Referer]] header, and
(c) **without** following [[RFC7231#header.location|HTTP redirects]].

For example:
Expand Down

0 comments on commit b439d86

Please sign in to comment.