@@ -2442,7 +2442,7 @@ run these steps:</p>
2442
2442
<p> The
2443
2443
`<dfn export http-header id=http-cross-origin-resource-policy><code>Cross-Origin-Resource-Policy</code></dfn> `
2444
2444
response <a for=/>header</a> can be used to require checking a <a for=/>request</a> 's
2445
- <a for=request>current url</a> 's <a for=URL >origin</a> against a <a for=/>request</a>' s
2445
+ <a for=request>current url</a> 's <a for=url >origin</a> against a <a for=/>request</a>' s
2446
2446
<a for=request>origin</a> when <a for=/>request</a> 's <a for=request>mode</a> is
2447
2447
"<code> no-cors</code> ".
2448
2448
@@ -2460,17 +2460,18 @@ Cross-Origin-Resource-Policy = %x73.61.6D.65 / %x73.61.6D.65.2D.73.69.74.65
2460
2460
2461
2461
<li>
2462
2462
<p> If <var> request</var> 's <a for=request>origin</a> is <a>same origin</a> with
2463
- <var> request</var> 's <a for=request>current url</a>' s <a for=URL >origin</a> , then return
2463
+ <var> request</var> 's <a for=request>current url</a>' s <a for=url >origin</a> , then return
2464
2464
<b> allowed</b> .
2465
2465
2466
2466
<p class=note> A cross-origin response redirecting to a same or same-site resource with the
2467
- `<code header> Cross-Origin-Resource-Policy</code> ` header specified does not affect anything.
2467
+ `<a http-header><code>Cross-Origin-Resource-Policy</code></a> ` header specified does not affect
2468
+ anything.
2468
2469
<!-- We could make this have an effect if we fix https://github.com/whatwg/fetch/pull/594 first,
2469
2470
but even then we normally do not let this have any effect for "no-cors" so it would be
2470
2471
somewhat inconsistent if it did here, but might still be better... -->
2471
2472
2472
2473
<li><p> Let <var> policy</var> be the <a>combined value</a> with
2473
- `<code header> Cross-Origin-Resource-Policy</code> ` and <var> response</var> 's
2474
+ `<a http- header><code> Cross-Origin-Resource-Policy</code></a > ` and <var> response</var> 's
2474
2475
<a for=response>header list</a> .
2475
2476
2476
2477
<li><p> If <var> policy</var> is `<code> same</code> `, then return <b> blocked</b> .
@@ -2481,9 +2482,9 @@ Cross-Origin-Resource-Policy = %x73.61.6D.65 / %x73.61.6D.65.2D.73.69.74.65
2481
2482
<ul class=brief>
2482
2483
<li><p><var> request</var> 's <a for=request>origin</a>' s <a for=origin>host</a>
2483
2484
<a>is a registrable domain suffix of or is equal to</a> <var> request</var> 's
2484
- <a for=request>current url</a> 's <a for=URL >host</a>
2485
+ <a for=request>current url</a> 's <a for=url >host</a>
2485
2486
2486
- <li><p><var> request</var> 's <a for=request>current url</a>' s <a for=URL >host</a>
2487
+ <li><p><var> request</var> 's <a for=request>current url</a>' s <a for=url >host</a>
2487
2488
<a>is a registrable domain suffix of or is equal to</a> <var> request</var> 's
2488
2489
<a for=request>origin</a> 's <a for=origin>host</a>
2489
2490
</ul>
0 commit comments