LGTM3

On 10/7/26 11:31 a.m., Alex Russell wrote:
LGTM2. Thanks for getting us closer to the spec.

On Wednesday, October 7, 2026 at 5:26:03 PM UTC+2 Chris Harrelson wrote:

    LGTM1

    On Fri, Oct 2, 2026 at 9:53 AM Chromestatus
    <[email protected]
    <mailto:[email protected]>> wrote:

        *Contact emails*
        [email protected]

        *Explainer*
        /No information provided/

        *Specification*
        https://wicg.github.io/background-fetch
        <https://wicg.github.io/background-fetch>

        *Summary*
        Starting in Chrome 157, the Background Fetch API now enforces
        Cross-Origin Resource Sharing (CORS). This update aligns
        Chromium's implementation with the intent of the [Background
        Fetch spec](https://wicg.github.io/background-fetch/
        <https://wicg.github.io/background-fetch/>). This ensures that
        Background Fetch requests are subject to the same security
        policies, such as Local Network Access checks. This update
        prevents sites from bypassing CORS (and other security policy
        checks) by using Background Fetch instead of regular
        [Fetch](https://fetch.spec.whatwg.org/
        <https://fetch.spec.whatwg.org/>).

        *Blink component*
        Blink>BackgroundFetch
        
<https://issues.chromium.org/issues?q=customfield1222907:%22Blink%3EBackgroundFetch%22>

        *Web Feature ID*
        background-fetch
        <https://webstatus.dev/features/background-fetch>

        *Motivation*
        This fixes a security issue where Background Fetch
        unintentionally bypasses security policies such as CORS (and
        CORP/COEP/DIP). (crbug.com/515243254
        <https://crbug.com/515243254> is our meta bug tracking all of
        the different web platform security issues with Background
        Fetch.)

        *Initial public proposal*
        /No information provided/

        *TAG review*
        /No information provided/

        *TAG review status*
        Not applicable

        *Goals for experimentation*
        None

        *Risks*


        *Interoperability and Compatibility*
        Overall usage of Background Fetch is extremely low. We
        considered completely deprecating and removing Background
        Fetch, which would be more disruptive. Treating Background
        Fetch requests the same as fetch() calls and requiring the
        same security policy enforcement (and server opt-ins via
        things like Access-Control-Allow-Origins) may cause some
        temporary breakage as sites and servers adjust (if they don't
        already have the necessary configuration for regular fetch
        requests).

        /Gecko/: No signal

        /WebKit/: No signal

        /Web developers/: No signals

        /Other signals/:

        *WebView application risks*

        Does this intent deprecate or change behavior of existing
        APIs, such that it has potentially high risk for Android
        WebView-based applications?

        /No information provided/


        *Debuggability*
        /No information provided/

        *Will this feature be supported on all six Blink platforms
        (Windows, Mac, Linux, ChromeOS, Android, and Android WebView)?*
        Yes

        *Is this feature fully tested by web-platform-tests
        
<https://chromium.googlesource.com/chromium/src/+/main/docs/testing/web_platform_tests.md>?*
        Yes


        *Flag name on about://flags*
        /No information provided/

        *Finch feature name*
        BackgroundFetchCorsEnforcement

        *Rollout plan*
        Will ship enabled for all users

        *Requires code in //chrome?*
        False

        *Estimated milestones*
        Shipping on desktop     157
        Shipping on Android     157



        *Anticipated spec changes*

        Open questions about a feature may be a source of future web
        compat or interop issues. Please list open issues (e.g. links
        to known github issues in the project for the feature
        specification) whose resolution may introduce web
        compat/interop risk (e.g., changing to naming or structure of
        the API in a non-backward-compatible way).

        None. This brings Chromium's implementation into alignment
        with the intent of the Background Fetch spec (which delegates
        security policy enforcement to the Fetch spec).

        *Link to entry on the Chrome Platform Status*
        https://chromestatus.com/feature/6210300985606144?gate=6167177091743744
        
<https://chromestatus.com/feature/6210300985606144?gate=6167177091743744>

        This intent message was generated by Chrome Platform Status
        <https://chromestatus.com>.

-- You received this message because you are subscribed to the
        Google Groups "blink-dev" group.
        To unsubscribe from this group and stop receiving emails from
        it, send an email to [email protected]
        <mailto:[email protected]>.
        To view this discussion visit
        
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6abfe174.b816ca50.7065.0796.GAE%40google.com
        
<https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6abfe174.b816ca50.7065.0796.GAE%40google.com?utm_medium=email&utm_source=footer>.

--
You received this message because you are subscribed to the Google Groups "blink-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/chromium.org/d/msgid/blink-dev/c91e0841-3db6-4a0c-bc01-4743558a2e28n%40chromium.org <https://groups.google.com/a/chromium.org/d/msgid/blink-dev/c91e0841-3db6-4a0c-bc01-4743558a2e28n%40chromium.org?utm_medium=email&utm_source=footer>.

--
You received this message because you are subscribed to the Google Groups 
"blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/fa8d4a86-53cb-406a-8b61-0c4ea5b5899e%40chromium.org.

Reply via email to