Mozilla should up its game in educating the public that Edge and Chrome aren't following the standards correctly. This seems IMHO pretty important in a world where everything relies on the browser to sandbox things.
Mozilla should up its game in educating the public that Edge and Chrome aren't following the standards correctly. This seems IMHO pretty important in a world where everything relies on the browser to sandbox things.
What's the difference in their CORS implementations? As far as I know all three major browser engines follow the modern spec.
For example, here are a pair of pages which make a cross-origin fetch for a resource that either does (yes-cors) or does not (no-cors) opt into cross-origin resource sharing. In all three browsers yes-cors displays the contents of the resource, and no-cors (correctly) displays "error".
https://www.kingfisherband.com/test/yes-cors
https://www.kingfisherband.com/test/no-cors
[1] With the exception of some standardized legacy cross-origin contexts like images, but then they all protect the contents in the same way.
I don’t think most people care about this. What they may care about is whether something works on their default browser, which is likely to be Edge or Safari or Chrome. Mozilla should instead target Microsoft and Google on the standards tracks and in forums where discussions on standards (and on security) happen.
Ultimately we have already passed the point where the web is defined by what Chrome (and to a limited extent what MobileSafari) does.
Which solution are you suggesting? Not having a standard?