fetch, XMLHttpRequest, WebSocket and EventSource are globals. No import, no permission. They
follow the specs, so MDN is the reference.
URLs must be absolute. A relative URL like
"/api/status" fails.Differences from a browser
- No CORS and no cookie jar. Any header (
User-Agent,Cookie,Origin, …) goes out as you set it. redirect: "manual"returns the real 3xx response, so you can readLocation.- The system proxy is ignored.
- Certificates are always checked; there’s no way to skip it.
- Network and certificate failures reject with a
TypeErrorwhosecause.codeis"ENETWORK"or"ECERT". A non-2xx status resolves normally, checkres.ok. XMLHttpRequestcan’t be synchronous (open(method, url, false)throws), andresponseXMLis alwaysnull.