You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<p>Implementations might implicitly allow a list of origins, such as the same-origin [<cite><aclass="bibref" href="#bib-rfc6454">RFC6454</a></cite>].</p>
826
827
</div>
827
828
</div>
828
-
829
-
<pid="req-server-wac-allow">Servers MUST advertise client’s access privileges on a resource by including the <code>WAC-Allow</code> HTTP header (<cite><ahref="#wac-allow" rel="rdfs:seeAlso">WAC-Allow</a></cite>) in the response of HTTP <code>GET</code> and <code>HEAD</code> requests.</p>
<p>Clients can discover access privileges on a resource by making an HTTP <code>HEAD</code> or <code>GET</code> request on the target resource, and checking the <code>WAC-Allow</code> header value for access parameters listing the allowed access modes per permission group (<cite><ahref="#wac-allow" rel="rdfs:seeAlso">WAC-Allow</a></cite>).</p>
835
-
</div>
836
-
</div>
837
-
838
-
<pid="req-server-cors-aceh-wac-allow">When a server participates in the <abbrtitle="Cross-Origin Resource Sharing">CORS</abbr> protocol [<cite><aclass="bibref" href="#bib-fetch">FETCH</a></cite>], the server MUST include <code>WAC-Allow</code> in the <code>Access-Control-Expose-Headers</code> field-value in the HTTP response.</p>
<pid="req-server-wac-allow">Servers MUST advertise client’s access privileges on a resource by including the <code>WAC-Allow</code> HTTP header (<cite><ahref="#wac-allow" rel="rdfs:seeAlso">WAC-Allow</a></cite>) in the response of HTTP <code>GET</code> and <code>HEAD</code> requests.</p>
<p>Clients can discover access privileges on a resource by making an HTTP <code>HEAD</code> or <code>GET</code> request on the target resource, and checking the <code>WAC-Allow</code> header value for access parameters listing the allowed access modes per permission group (<cite><ahref="#wac-allow" rel="rdfs:seeAlso">WAC-Allow</a></cite>).</p>
920
+
</div>
921
+
</div>
922
+
923
+
<pid="req-server-cors-aceh-wac-allow">When a server participates in the <abbrtitle="Cross-Origin Resource Sharing">CORS</abbr> protocol [<cite><aclass="bibref" href="#bib-fetch">FETCH</a></cite>], the server MUST include <code>WAC-Allow</code> in the <code>Access-Control-Expose-Headers</code> field-value in the HTTP response.</p>
0 commit comments