Regarding the CORS spec: Shouldn't "list of exposed headers" be added to the resource policy bullet list? Or is that already covered by "list of supported headers"?
http://www.w3.org/TR/access-control/#resource-processing-model -- Vladimir Dzhuvinov :: software.dzhuvinov.com
