rfcs
rfcs copied to clipboard
Allow server generated header values
Allow a server to generate values for header configuration as detailed in https://github.com/npm/rfcs/pull/138
This rfc is in addition to the aforementioned rfc
Does this have privacy concerns? Just like cookies, it seems like it would let a registry track unauthenticated users (and auth’d users’ machines) without the user’s knowledge or permission.
Removing from agenda for now as this needs to come after https://github.com/npm/rfcs/pull/138 &, as @ljharb noted & we spoke briefly on the call, this sounds a lot like cookies & we may not want to reinvent the wheel here.