@@ -2526,7 +2526,7 @@ response <a for=/>header</a> can be used to require checking a <a for=/>request<
2526
2526
<p> Its <a for=header>value</a> <a>ABNF</a> :
2527
2527
2528
2528
<pre>
2529
- Cross-Origin-Resource-Policy = %x73.61.6D.65 / %x73.61.6D.65.2D.73.69.74.65 ; "same" / "same-site", case-sensitive</pre>
2529
+ Cross-Origin-Resource-Policy = %x73.61.6D.65.2D.6F.72.69.67.69.6E / %x73.61.6D.65.2D.73.69.74.65 ; "same-origin " / "same-site", case-sensitive</pre>
2530
2530
2531
2531
<p> To perform a <dfn>cross-origin resource policy check</dfn> , given a <var> request</var> and
2532
2532
<var> response</var> , run these steps:</p>
@@ -2550,11 +2550,11 @@ Cross-Origin-Resource-Policy = %x73.61.6D.65 / %x73.61.6D.65.2D.73.69.74.65
2550
2550
`<a http-header><code>Cross-Origin-Resource-Policy</code></a> ` and <var> response</var> 's
2551
2551
<a for=response>header list</a> .
2552
2552
2553
- <p class=note> This means that `<code> Cross-Origin-Resource-Policy: same-site, same</code> ` ends up
2554
- as <b> allowed</b> below as it will never match anything. Two or more
2553
+ <p class=note> This means that `<code> Cross-Origin-Resource-Policy: same-site, same-origin </code> `
2554
+ ends up as <b> allowed</b> below as it will never match anything. Two or more
2555
2555
`<a http-header><code>Cross-Origin-Resource-Policy</code></a> ` headers will have the same effect.
2556
2556
2557
- <li><p> If <var> policy</var> is `<code> same</code> `, then return <b> blocked</b> .
2557
+ <li><p> If <var> policy</var> is `<code> same-origin </code> `, then return <b> blocked</b> .
2558
2558
2559
2559
<li><p> If <var> request</var> 's <a for=request>origin</a>' s <a for=url>host</a> is <a>same site</a>
2560
2560
with <var> request</var> 's <a for=request>current url</a>' s <a for=url>host</a> , then return
0 commit comments