Local overrides should playback CORS/security headers

53 views
Skip to first unread message

Matteo Fogli

unread,
Mar 27, 2018, 6:46:35 AM3/27/18
to Chrome DevTools
Currently local overrides work for same domain or content that is not validated against security policies.
For instance, it is not possible to override a font file (for instance, to test subsets or variants in compression) due to LO sending the file without the Cross Origin headers it has when served from its origin.

To make full use of LO Chrome should either allow to add custom headers or playback headers sent from the origin server (either by caching them or by preflighting the resource)

Looking forward to your feedback. 
I can provide a real world example.

Matteo

Kayce Basques

unread,
Apr 5, 2018, 7:10:36 PM4/5/18
to Chrome DevTools
Sounds reasonable. I forwarded your feedback to the relevant engineer.

Kayce Basques

unread,
Apr 5, 2018, 7:14:07 PM4/5/18
to Chrome DevTools
Hey Matteo, engineer replied that a realworld example with steps to reproduce would be helpful.


On Tuesday, March 27, 2018 at 3:46:35 AM UTC-7, Matteo Fogli wrote:
Reply all
Reply to author
Forward
0 new messages