Contact emails [email protected]
Explainer No information provided Specification https://wicg.github.io/background-fetch Summary Starting in Chrome 157, the Background Fetch API now enforces Cross-Origin Resource Sharing (CORS). This update aligns Chromium's implementation with the intent of the [Background Fetch spec](https://wicg.github.io/background-fetch/). This ensures that Background Fetch requests are subject to the same security policies, such as Local Network Access checks. This update prevents sites from bypassing CORS (and other security policy checks) by using Background Fetch instead of regular [Fetch](https://fetch.spec.whatwg.org/). Blink component Blink>BackgroundFetch Web Feature ID background-fetch Motivation This fixes a security issue where Background Fetch unintentionally bypasses security policies such as CORS (and CORP/COEP/DIP). (crbug.com/515243254 is our meta bug tracking all of the different web platform security issues with Background Fetch.) Initial public proposal No information provided TAG review No information provided TAG review status Not applicable Goals for experimentation None Risks Interoperability and Compatibility Overall usage of Background Fetch is extremely low. We considered completely deprecating and removing Background Fetch, which would be more disruptive. Treating Background Fetch requests the same as fetch() calls and requiring the same security policy enforcement (and server opt-ins via things like Access-Control-Allow-Origins) may cause some temporary breakage as sites and servers adjust (if they don't already have the necessary configuration for regular fetch requests). Gecko: No signal WebKit: No signal Web developers: No signals Other signals: WebView application risks Does this intent deprecate or change behavior of existing APIs, such that it has potentially high risk for Android WebView-based applications? No information provided Debuggability No information provided Will this feature be supported on all six Blink platforms (Windows, Mac, Linux, ChromeOS, Android, and Android WebView)? Yes Is this feature fully tested by web-platform-tests? Yes Flag name on about://flags No information provided Finch feature name BackgroundFetchCorsEnforcement Rollout plan Will ship enabled for all users Requires code in //chrome? False Estimated milestones Shipping on desktop 157 Shipping on Android 157 Anticipated spec changes Open questions about a feature may be a source of future web compat or interop issues. Please list open issues (eg links to known github issues in the project for the feature specification) whose resolution may introduce web compat/interop risk (eg, changing to naming or structure of the API in a non-backward-compatible way). None. This brings Chromium's implementation into alignment with the intent of the Background Fetch spec (which delegates security policy enforcement to the Fetch spec). Link to entry on the Chrome Platform Status https://chromestatus.com/feature/6210300985606144?gate=6167177091743744 This intent message was generated by Chrome Platform Status. -- You received this message because you are subscribed to the Google Groups "blink-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6abfe174.b816ca50.7065.0796.GAE%40google.com.
