You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Jul 23, 2022. It is now read-only.
Currently, we allow embedded credentials in URLs, because I haven't put in a check to explicitly disallow them. There's a comment to the effect that they're not supposed to be allowed in the Chrome codebase, and I could swear at one point I saw the code that actually implemented this check, but I can't find it now.
I think this might be security-relevant but am not super clear on the details. I wish there was an actual spec...
The text was updated successfully, but these errors were encountered:
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Currently, we allow embedded credentials in URLs, because I haven't put in a check to explicitly disallow them. There's a comment to the effect that they're not supposed to be allowed in the Chrome codebase, and I could swear at one point I saw the code that actually implemented this check, but I can't find it now.
I think this might be security-relevant but am not super clear on the details. I wish there was an actual spec...
The text was updated successfully, but these errors were encountered: