diff --git a/spec/index.bs b/spec/index.bs index f5298bdbc..c213c5021 100644 --- a/spec/index.bs +++ b/spec/index.bs @@ -579,8 +579,9 @@ by the [=IDP=]. The manifest discovery endpoint is fetched: -(a) **without** cookies and -(b) **with** a special [[#Sec-FedCM-CSRF]] header, and +(a) **without** cookies, +(b) **with** a special [[#Sec-FedCM-CSRF]] header, +(c) **without** a [[RFC7231#header.referer|Referer]] header, and (c) **without** following [[RFC7231#header.location|HTTP redirects]]. For example: