FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

No default withCredentials. Updated version of #47 by gsf · Pull Request #53 · browserify/http-browserify · GitHub

No default withCredentials. Updated version of #47 - #53

Open
gsf wants to merge 1 commit into
browserify:masterfrom
gsf:withCredentials-no-default
Open

No default withCredentials. Updated version of #47#53
gsf wants to merge 1 commit into
browserify:masterfrom
gsf:withCredentials-no-default

Conversation

gsf commented Jun 23, 2014

Copy link
Copy Markdown

Any reason to alter the default for xhr.withCredentials?

gobengo commented Jul 8, 2014

Copy link
Copy Markdown

I think it is a bad idea to change the default on such an important flag without a major version bump, or at least minor.

Though I would say if this was a fresh project that withCredentials should be false by default.

gsf commented Jul 8, 2014

Copy link
Copy Markdown
Author

As discussed at naugtur/xhr#33 (click "Show outdated diff"), some believe the withCredentials default in the spec was a mistake, as was the Access-Control-Allow-Origin wildcard. I haven't found many resources to back this up, however. The commented text at http://enable-cors.org/server_nginx.html suggests this, but others (including http://fetch.spec.whatwg.org/#basic-safe-cors-protocol-setup) seem to favor the wildcard and the default of false.

Copy link
Copy Markdown

I would like to see this merged since withCredentials default to true prevents accessing resources on many servers and the solution might not be obvious for users. Especially if your like me using http-browserify through request browserified.

Resources examples:
http://data-gov.tw.rpi.edu/raw/1576/data-1576.nt.gz
http://ftp.ebi.ac.uk/pub/databases/ensembl/encode/integration_data_jan2011/hub.txt

eush77 commented Nov 5, 2014

Copy link
Copy Markdown

Please merge. The current default behavior is totally unexpected.

Copy link
Copy Markdown

Holy shit, please merge. That took me forever to figure out.

Copy link
Copy Markdown

Any update on if/when this will get merged?

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants


Back | FazBrowse Home | New Git URL