← Back to release summary

Tainted origin flag applied to Resource Timing

Category
Performance
Type
No developer-visible change
Status
Enabled by default (Chrome 92)
Intent stage
Shipped

Summary

Accounts for the tainted origin flag when computing whether a fetched resource passes the timing allow origin check. The Timing Allow Origin check is used in Resource Timing to determine whether the page has the right to receive detailed timing information about a resource used in the page. The tainted origin flag impacts this check in cases where there are multiple redirects that cross origins. In those cases, the header should be '*', i.e. can no longer be a specific origin.

Standards & signals

View on chromestatus.com