Contact emails
[email protected]

Explainer
No information provided


Specification
https://wicg.github.io/background-fetch


Summary
Starting in Chrome 157, the Background Fetch API now enforces Cross-Origin 
Resource Sharing (CORS). This update aligns Chromium's implementation with the 
intent of the [Background Fetch 
spec](https://wicg.github.io/background-fetch/). This ensures that Background 
Fetch requests are subject to the same security policies, such as Local Network 
Access checks. This update prevents sites from bypassing CORS (and other 
security policy checks) by using Background Fetch instead of regular 
[Fetch](https://fetch.spec.whatwg.org/).


Blink component
Blink>BackgroundFetch


Web Feature ID
background-fetch


Motivation
This fixes a security issue where Background Fetch unintentionally bypasses 
security policies such as CORS (and CORP/COEP/DIP). (crbug.com/515243254 is our 
meta bug tracking all of the different web platform security issues with 
Background Fetch.)


Initial public proposal
No information provided


TAG review
No information provided


TAG review status
Not applicable


Goals for experimentation
None


Risks




Interoperability and Compatibility
Overall usage of Background Fetch is extremely low. We considered completely 
deprecating and removing Background Fetch, which would be more disruptive. 
Treating Background Fetch requests the same as fetch() calls and requiring the 
same security policy enforcement (and server opt-ins via things like 
Access-Control-Allow-Origins) may cause some temporary breakage as sites and 
servers adjust (if they don't already have the necessary configuration for 
regular fetch requests).

Gecko: No signal

WebKit: No signal

Web developers: No signals

Other signals:


WebView application risks

Does this intent deprecate or change behavior of existing APIs, such that it 
has potentially high risk for Android WebView-based applications?
No information provided



Debuggability
No information provided


Will this feature be supported on all six Blink platforms (Windows, Mac, Linux, 
ChromeOS, Android, and Android WebView)?
Yes


Is this feature fully tested by web-platform-tests?
Yes



Flag name on about://flags
No information provided


Finch feature name
BackgroundFetchCorsEnforcement


Rollout plan
Will ship enabled for all users


Requires code in //chrome?
False


Estimated milestones


Shipping on desktop 157

Shipping on Android 157




Anticipated spec changes

Open questions about a feature may be a source of future web compat or interop 
issues. Please list open issues (eg links to known github issues in the project 
for the feature specification) whose resolution may introduce web 
compat/interop risk (eg, changing to naming or structure of the API in a 
non-backward-compatible way).
None. This brings Chromium's implementation into alignment with the intent of 
the Background Fetch spec (which delegates security policy enforcement to the 
Fetch spec).


Link to entry on the Chrome Platform Status
https://chromestatus.com/feature/6210300985606144?gate=6167177091743744


This intent message was generated by Chrome Platform Status.

-- 
You received this message because you are subscribed to the Google Groups 
"blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6abfe174.b816ca50.7065.0796.GAE%40google.com.

Reply via email to