@@ -1902,8 +1902,8 @@ for=/>request</a> <var>request</var>, run theses steps:
1902
1902
<li><p> If <var> request</var> 's <a for=request>client</a> is null, return true.</p>
1903
1903
1904
1904
<li><p> If <var> request</var> 's <a for=request>client</a>' s <a for="environment settings
1905
- object">embedder policy</a> is not " <code> <a for="embedder policy
1906
- value">credentialless</a> </code> ", return true.</p>
1905
+ object">embedder policy</a> is not
1906
+ " <code> <a for="embedder policy value">credentialless</a></code> ", return true.</p>
1907
1907
1908
1908
<li><p> If <var> request</var> 's <a for=request>origin</a> is <a>same origin</a> with
1909
1909
<var> request</var> 's <a for=request>current URL</a>' s <a for=url>origin</a> , return true.</p>
@@ -1997,8 +1997,8 @@ being provided to an API that didn't make a range request. See the flag's usage
1997
1997
description of the attack.
1998
1998
1999
1999
<p> A <a for=/>response</a> has an associated <dfn for=response
2000
- id=concept-response-request-include-credentials> request-include-credentials</dfn> , which is
2001
- initially set .
2000
+ id=concept-response-request-include-credentials> request-include-credentials</dfn> (a boolean) , which
2001
+ is initially true .
2002
2002
2003
2003
<p> A <a for=/>response</a> has an associated
2004
2004
<dfn for=response id=concept-response-timing-allow-passed>timing allow passed flag</dfn> , which is
@@ -4620,7 +4620,7 @@ steps. They return a <a for=/>response</a>.
4620
4620
4621
4621
<p> is true; otherwise false.
4622
4622
4623
- <li><p> If <a>Cross-Origin-Embedder-Policy allows credentials</a> with <var> request</var> is
4623
+ <li><p> If <a>Cross-Origin-Embedder-Policy allows credentials</a> with <var> request</var> returns
4624
4624
false, set <var> includeCredentials</var> to false.</p>
4625
4625
4626
4626
<li><p> Let <var> contentLength</var> be <var> httpRequest</var> 's <a for=request>body</a>' s
0 commit comments