3 ms·
So lemme try to clear this up. You are right in that brotli decoding is only supposed to work in secure contexts (so technically not just HTTPS, btw -- localho
by rhblake 9y ago
So lemme try to clear this up.
You are right in that brotli decoding is only supposed to work in secure contexts (so technically not just HTTPS, btw -- localhost is also considered a secure context, see https://bugs.chromium.org/p/chromium/issues/detail?id=624426 https://bugs.chromium.org/p/chromium/issues/detail?id=624426).
Eridius is right in that it currently does work over insecure HTTP in Chrome, as confirmed in this open bug: https://bugs.chromium.org/p/chromium/issues/detail?id=579606 https://bugs.chromium.org/p/chromium/issues/detail?id=579606 -- in which one Chromium dev comments "Decoding brotli even if it isn't requested is both bug and feature. It allows developers to test brotli without setting up https serving." Seems like they concluded that it is indeed a bug, however.
Reality and specifications often diverge...
(I do think not supporting gzip is absolutely bizarre, but that's another issue.)