<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>28861</bug_id>
          
          <creation_ts>2015-06-28 18:28:57 +0000</creation_ts>
          <short_desc>Section 6.2 Preflight Request, step 10, second note: &quot;Access-Control-Allow-Headers&quot; instead of &quot;Access-Control-Request-Headers&quot;</short_desc>
          <delta_ts>2015-07-01 17:48:28 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebAppsSec</product>
          <component>CORS</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>NEW</bug_status>
          <resolution></resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Claude Pache">claude.pache</reporter>
          <assigned_to name="Anne">annevk</assigned_to>
          <cc>hillbrad</cc>
    
    <cc>mike</cc>
    
    <cc>public-webappsec</cc>
    
    <cc>wseltzer</cc>
          
          <qa_contact name="This bug has no owner yet - up for the taking">dave.null</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>121514</commentid>
    <comment_count>0</comment_count>
    <who name="Claude Pache">claude.pache</who>
    <bug_when>2015-06-28 18:28:57 +0000</bug_when>
    <thetext>In http://www.w3.org/TR/cors/#resource-preflight-requests
Section 6.2 Preflight Request, step 10, second Note:

  &quot;Since the list of headers can be unbounded, simply returning supported headers from Access-Control-Allow-Headers can be enough.&quot;

s/Access-Control-Allow-Headers/Access-Control-Request-Headers/</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>121521</commentid>
    <comment_count>1</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2015-06-29 09:32:53 +0000</bug_when>
    <thetext>1) That document is obsolete, use https://fetch.spec.whatwg.org/ instead.
2) If we do any kind of fix here, removing that statement would be better since that proposed fix does not really make it any better.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>121530</commentid>
    <comment_count>2</comment_count>
    <who name="Claude Pache">claude.pache</who>
    <bug_when>2015-06-30 09:41:34 +0000</bug_when>
    <thetext>&gt; 1) That document is obsolete, use https://fetch.spec.whatwg.org/ instead.

Thanks for the information.

An issue is that (1) there is no clue in the w3c document suggesting that it should be considered as obsolete, and (2) references found on the web routinely refers to the w3c document as &quot;the CORS specification&quot; without mentioning the whatwg document.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>121531</commentid>
    <comment_count>3</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2015-06-30 09:45:53 +0000</bug_when>
    <thetext>Brad, can we mark CORS as obsolete? Or update it to point to the latest version? I keep getting private emails about it too suggesting we&apos;re wasting a lot of people their time.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>