LGTM2. Thanks for getting us closer to the spec.

On Wednesday, October 7, 2026 at 5:26:03 PM UTC+2 Chris Harrelson wrote:

> LGTM1
>
> On Fri, Oct 2, 2026 at 9:53 AM Chromestatus <
> [email protected]> wrote:
>
>> *Contact emails*
>> [email protected]
>>
>> *Explainer*
>> *No information provided*
>>
>> *Specification*
>> https://wicg.github.io/background-fetch 
>>
>> *Summary*
>> Starting in Chrome 157, the Background Fetch API now enforces 
>> Cross-Origin Resource Sharing (CORS). This update aligns Chromium's 
>> implementation with the intent of the [Background Fetch spec](
>> https://wicg.github.io/background-fetch/). This ensures that Background 
>> Fetch requests are subject to the same security policies, such as Local 
>> Network Access checks. This update prevents sites from bypassing CORS (and 
>> other security policy checks) by using Background Fetch instead of regular 
>> [Fetch](https://fetch.spec.whatwg.org/). 
>>
>> *Blink component*
>> Blink>BackgroundFetch 
>> <https://issues.chromium.org/issues?q=customfield1222907:%22Blink%3EBackgroundFetch%22>
>>
>> *Web Feature ID*
>> background-fetch <https://webstatus.dev/features/background-fetch> 
>>
>> *Motivation*
>> This fixes a security issue where Background Fetch unintentionally 
>> bypasses security policies such as CORS (and CORP/COEP/DIP). (
>> crbug.com/515243254 is our meta bug tracking all of the different web 
>> platform security issues with Background Fetch.) 
>>
>> *Initial public proposal*
>> *No information provided*
>>
>> *TAG review*
>> *No information provided* 
>>
>> *TAG review status*
>> Not applicable
>>
>> *Goals for experimentation*
>> None 
>>
>> *Risks*
>>
>>
>> *Interoperability and Compatibility*
>> Overall usage of Background Fetch is extremely low. We considered 
>> completely deprecating and removing Background Fetch, which would be more 
>> disruptive. Treating Background Fetch requests the same as fetch() calls 
>> and requiring the same security policy enforcement (and server opt-ins via 
>> things like Access-Control-Allow-Origins) may cause some temporary breakage 
>> as sites and servers adjust (if they don't already have the necessary 
>> configuration for regular fetch requests). 
>>
>> *Gecko*: No signal
>>
>> *WebKit*: No signal
>>
>> *Web developers*: No signals
>>
>> *Other signals*:
>>
>> *WebView application risks*
>>
>> Does this intent deprecate or change behavior of existing APIs, such that 
>> it has potentially high risk for Android WebView-based applications? 
>> *No information provided* 
>>
>>
>> *Debuggability*
>> *No information provided* 
>>
>> *Will this feature be supported on all six Blink platforms (Windows, Mac, 
>> Linux, ChromeOS, Android, and Android WebView)?*
>> Yes
>>
>> *Is this feature fully tested by web-platform-tests 
>> <https://chromium.googlesource.com/chromium/src/+/main/docs/testing/web_platform_tests.md>?*
>> Yes 
>>
>>
>> *Flag name on about://flags*
>> *No information provided* 
>>
>> *Finch feature name*
>> BackgroundFetchCorsEnforcement 
>>
>> *Rollout plan*
>> Will ship enabled for all users
>>
>> *Requires code in //chrome?*
>> False
>>
>> *Estimated milestones*
>> Shipping on desktop 157 
>> Shipping on Android 157 
>>
>> *Anticipated spec changes*
>>
>> Open questions about a feature may be a source of future web compat or 
>> interop issues. Please list open issues (e.g. links to known github issues 
>> in the project for the feature specification) whose resolution may 
>> introduce web compat/interop risk (e.g., changing to naming or structure of 
>> the API in a non-backward-compatible way). 
>> None. This brings Chromium's implementation into alignment with the 
>> intent of the Background Fetch spec (which delegates security policy 
>> enforcement to the Fetch spec).
>>
>> *Link to entry on the Chrome Platform Status*
>> https://chromestatus.com/feature/6210300985606144?gate=6167177091743744
>>
>> This intent message was generated by Chrome Platform Status 
>> <https://chromestatus.com>. 
>>
>> -- 
>> You received this message because you are subscribed to the Google Groups 
>> "blink-dev" group.
>> To unsubscribe from this group and stop receiving emails from it, send an 
>> email to [email protected].
>> To view this discussion visit 
>> https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6abfe174.b816ca50.7065.0796.GAE%40google.com
>>  
>> <https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6abfe174.b816ca50.7065.0796.GAE%40google.com?utm_medium=email&utm_source=footer>
>> .
>>
>

-- 
You received this message because you are subscribed to the Google Groups 
"blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/c91e0841-3db6-4a0c-bc01-4743558a2e28n%40chromium.org.

Reply via email to