As there seems to be no danger in allowing this header for same origin requests, I'd suggest removing it from the list of forbidden headers. As mentioned in this thread, there are valid reasons to control it explicitly.
Actually, I suppose we can also allow it for cross-origin requests now the server has to explicitly opt-in for each and every header.
-- Anne van Kesteren http://annevankesteren.nl/
