官术网_书友最值得收藏!

Considering the origin of entities

Access to DOM elements is allowed only when the request scheme, hostname, and port number match those of the current URI. A subdomain cannot share DOM elements with the parent domain.

  • Scheme in web applications is typically http:// or https://
  • Hostname is typically the domain name plus TLD, or the unique IP address
  • Port number:
    • Typically, port 80 is implicit in http://
    • 443 for SSL over https://

If the Scheme, Hostname, and port number do not match the DOM element, then resource sharing is prohibited as they do not share the same origin. Considering the domain http://www.example.com, the following table provides various combinations of matching and mismatching origins:

Internet Explorer exception policy

Internet Explorer (IE) implements two major differences when it comes to the same-origin policy:

  • IE Trust Zones allow different domains: If both domains are in a highly trusted zone, then the same-origin policy limitations are not applied.
  • Port is ignored: IE ignores the port in same origin components. These URIs are considered from the same origin:
    • http://www.example.com:80/dir/page1.html
    • http://www.example.com:81/dir/page1.html

      Tip

      These exceptions in Internet Explorer are non-standard and are not supported in other browsers. If an application is only viewed in Windows RT mobile or Internet Explorer, then these exceptions could be useful.

主站蜘蛛池模板: 咸阳市| 师宗县| 望谟县| 于田县| 茂名市| 昭苏县| 固镇县| 金阳县| 清徐县| 灌阳县| 河东区| 钦州市| 永善县| 定日县| 满洲里市| 全椒县| 贞丰县| 六盘水市| 塔城市| 射洪县| 博罗县| 平阳县| 尚志市| 文安县| 福海县| 河源市| 旅游| 体育| 射洪县| 襄汾县| 平乡县| 周至县| 盱眙县| 尉犁县| 龙海市| 迁西县| 潮安县| 静海县| 汤阴县| 台东市| 阜宁县|