w3c / w3c/trace-context

Requirements for CORS safe-list

Open
#405 3 comments 0 reactions 1 assignee View on GitHub

@dyladan is already working on this.

Since Jul 6, 2021.

revisit-later
Dominant language
Python
Stars
510
Forks
80
PR merge metrics
No merged PRs in 30d

Description

The CORS safelist is very tightly restricted. There are currently only 4 safe headers

  • Accept
  • Accept-Language
  • Content-Language
  • Content-Type

Even those are tightly restricted.

  • For Accept-Language and Content-Language: can only have values consisting of 0-9A-Za-z, space or *,-.;=.
  • For Accept and Content-Type: can't contain a CORS-unsafe request header byte: "():<>?@[\]{}, Delete, Tab and control characters: 0x00 to 0x19.
  • For Content-Type: needs to have a MIME type of its parsed value (ignoring parameters) of either application/x-www-form-urlencodedmultipart/form-data, or text/plain.
  • For any header: the value’s length can't be greater than 128.
  • The length of all header values combined can't be greater than 1024

The last 2 restrictions are the ones that I think are the biggest issues

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.